Getting Data In

Repository for sourcetype configuration for common log formats?

the_wolverine
Champion

Is there a repository for common log formats? I have Tomcat boot.log that is not line breaking correctly, most likely because it has been assigned a custom sourcetype.

If Splunk knows about this sourcetype, how would I reference the proper configuration to get my line breaking to work properly for this source?

0 Karma

tnesavich_splun
Splunk Employee
Splunk Employee

Love the idea! I am not seeing that Splunk has this. However, this is similar:
http://gosplunk.com/

Also, as it relates to your question I would look at how this is done when using the Splunk Add-on for Tomcat (or maybe even use it):
https://splunkbase.splunk.com/app/2911/

Here are is another supporting link for installation / configuration should you go that route:
http://docs.splunk.com/Documentation/AddOns/released/Tomcat/Setup

0 Karma
Get Updates on the Splunk Community!

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

  Now On Demand  Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research ...

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...