Is there a repository for common log formats? I have Tomcat boot.log that is not line breaking correctly, most likely because it has been assigned a custom sourcetype.
If Splunk knows about this sourcetype, how would I reference the proper configuration to get my line breaking to work properly for this source?
Love the idea! I am not seeing that Splunk has this. However, this is similar:
Also, as it relates to your question I would look at how this is done when using the Splunk Add-on for Tomcat (or maybe even use it):
Here are is another supporting link for installation / configuration should you go that route: