Getting Data In

cannot find sourcetype squid

njathan
Explorer

I am trying to analyse a squid access log for top 10 reports (top sources, top destinations, etc.)

I imported the log file in Manager » Data inputs » Files & Directories » Add New

When i keep the sourcetype=automatic, it does not seem to identify the source destination etc fields... just bundles them into one huge field, which is useless.

Elsewhere in this forum, i found someone's using sourcetype=squid_access. Where is this available for the latest version (4.1.4)? If not this, what is the best way of analysing squid logs in splunk?

Tags (1)
1 Solution

rroberts
Splunk Employee
Splunk Employee

When you set sourcetype to manual you should be able to type squid_access in the box below.

View solution in original post

0 Karma

rroberts
Splunk Employee
Splunk Employee

When you set sourcetype to manual you should be able to type squid_access in the box below.

0 Karma

njathan
Explorer

thanks rroberts 🙂

0 Karma

rroberts
Splunk Employee
Splunk Employee

I see what you mean now have you seen this doc? http://www.splunk.com/wiki/Community:Field_extractions_for_Squid_data
There is a props.conf and transforms.conf example for squid field extraction that might be helpful.

0 Karma

njathan
Explorer

actually manually typing access_squid does not help in that fields like TCP_MISS/200, CONNECT, http://mail.google.com etc in the log dont get classified into separate fields. Tried the 'extract fields' options, but i am poor at regex, and would be helpful if there is a ready plugin that lets splunk categorize the fields accordingly. (Which is not happening right now.)

0 Karma

njathan
Explorer

the 'drop-down' list appears when i choose the 'From list' option in the 'Set sourcetype' section... Manual sourcetype does not give any listing...

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

 Prepare to elevate your security operations with the powerful upgrade to Splunk Enterprise Security 8.x! This ...

Get Early Access to AI Playbook Authoring: Apply for the Alpha Private Preview ...

Passionate about security automation? Apply now to our AI Playbook Authoring Alpha private preview ...

Reduce and Transform Your Firewall Data with Splunk Data Management

Managing high-volume firewall data has always been a challenge. Noisy events and verbose traffic logs often ...