Getting Data In

breaking down segments of events

nina15
Communicator

hi...

I need to break down my event logs.
I'm getting confused in configuring transform.conf, props.conf, etc...

this a sample of one line of my data:

I, [2011-04-01T00:01:04.883503 #1023]  INFO -- : [2011-04-01 00:01:03,153.30.11.29,12345,192.225.180.55,654,bumiflow.com.my,MX,IN]

(for confidentiality reasons, I've changed data values... but the format follows the same)

so currently, splunk is able to map the source ip, and also identifies the time.

I want to break down all the rest of the event as well based on resource records (MX, A, AAAA, etc.), domains, etc..
firstly, Can I do that from splunk manager? probably "Manager>fiels"...
if not, can you guide me through configuring the conf files..

thank you.

0 Karma

ignetops
Explorer
0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...