Getting Data In

Search on non formatted log files

sushmitha_mj
Communicator

I am working on getting some datapower logs into Splunk. The problem is the logs are not in CSV format, there are no delimiters. The data is usually follows certain field pattern, but sometimes it does not. I know if I insert this logs into splunk I can search for particular words like "error" etc in the log and display their count etc , but if I want to do more operations on this log, how do I do them?
I could not find splunk documentation relating to handling such data. If there are please share link.

Tags (2)
0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

Splunk is excellent at handling unstructured data. Just add the data and manipulate it with the interactive field extractor (IFX), or rex & erex commands. Biggest thing is you want to get your event's broke into different events, one line per event (usually but not always the case), etc. You do that with LINE_BREAKER, MUST_BREAK_BEFORE, etc. See props.conf documentation (link is provided here: props.conf) and read the event breaking portions.

Once you have the data in splunk it should be easy to use the IFX to pull out fields you want.

View solution in original post

0 Karma

jkat54
SplunkTrust
SplunkTrust

Splunk is excellent at handling unstructured data. Just add the data and manipulate it with the interactive field extractor (IFX), or rex & erex commands. Biggest thing is you want to get your event's broke into different events, one line per event (usually but not always the case), etc. You do that with LINE_BREAKER, MUST_BREAK_BEFORE, etc. See props.conf documentation (link is provided here: props.conf) and read the event breaking portions.

Once you have the data in splunk it should be easy to use the IFX to pull out fields you want.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...