Getting Data In

Search on non formatted log files

sushmitha_mj
Communicator

I am working on getting some datapower logs into Splunk. The problem is the logs are not in CSV format, there are no delimiters. The data is usually follows certain field pattern, but sometimes it does not. I know if I insert this logs into splunk I can search for particular words like "error" etc in the log and display their count etc , but if I want to do more operations on this log, how do I do them?
I could not find splunk documentation relating to handling such data. If there are please share link.

Tags (2)
0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

Splunk is excellent at handling unstructured data. Just add the data and manipulate it with the interactive field extractor (IFX), or rex & erex commands. Biggest thing is you want to get your event's broke into different events, one line per event (usually but not always the case), etc. You do that with LINE_BREAKER, MUST_BREAK_BEFORE, etc. See props.conf documentation (link is provided here: props.conf) and read the event breaking portions.

Once you have the data in splunk it should be easy to use the IFX to pull out fields you want.

View solution in original post

0 Karma

jkat54
SplunkTrust
SplunkTrust

Splunk is excellent at handling unstructured data. Just add the data and manipulate it with the interactive field extractor (IFX), or rex & erex commands. Biggest thing is you want to get your event's broke into different events, one line per event (usually but not always the case), etc. You do that with LINE_BREAKER, MUST_BREAK_BEFORE, etc. See props.conf documentation (link is provided here: props.conf) and read the event breaking portions.

Once you have the data in splunk it should be easy to use the IFX to pull out fields you want.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...

Build and Launch AI Agents from Your Splunk Workflows

Replay Tech Talk Build and Launch AI Agents from Your Splunk Workflows     We’ve all been there: juggling ...

index This | What kind of room has no doors?

IndexEducation Cover Art Banner Cisco.png August 2026 Edition  Hayyy Splunk Education Enthusiasts and the ...