Getting Data In

Search on non formatted log files

sushmitha_mj
Communicator

I am working on getting some datapower logs into Splunk. The problem is the logs are not in CSV format, there are no delimiters. The data is usually follows certain field pattern, but sometimes it does not. I know if I insert this logs into splunk I can search for particular words like "error" etc in the log and display their count etc , but if I want to do more operations on this log, how do I do them?
I could not find splunk documentation relating to handling such data. If there are please share link.

Tags (2)
0 Karma
1 Solution

jkat54
SplunkTrust
SplunkTrust

Splunk is excellent at handling unstructured data. Just add the data and manipulate it with the interactive field extractor (IFX), or rex & erex commands. Biggest thing is you want to get your event's broke into different events, one line per event (usually but not always the case), etc. You do that with LINE_BREAKER, MUST_BREAK_BEFORE, etc. See props.conf documentation (link is provided here: props.conf) and read the event breaking portions.

Once you have the data in splunk it should be easy to use the IFX to pull out fields you want.

View solution in original post

0 Karma

jkat54
SplunkTrust
SplunkTrust

Splunk is excellent at handling unstructured data. Just add the data and manipulate it with the interactive field extractor (IFX), or rex & erex commands. Biggest thing is you want to get your event's broke into different events, one line per event (usually but not always the case), etc. You do that with LINE_BREAKER, MUST_BREAK_BEFORE, etc. See props.conf documentation (link is provided here: props.conf) and read the event breaking portions.

Once you have the data in splunk it should be easy to use the IFX to pull out fields you want.

0 Karma
Get Updates on the Splunk Community!

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...