Getting Data In

cannot find sourcetype squid

njathan
Explorer

I am trying to analyse a squid access log for top 10 reports (top sources, top destinations, etc.)

I imported the log file in Manager » Data inputs » Files & Directories » Add New

When i keep the sourcetype=automatic, it does not seem to identify the source destination etc fields... just bundles them into one huge field, which is useless.

Elsewhere in this forum, i found someone's using sourcetype=squid_access. Where is this available for the latest version (4.1.4)? If not this, what is the best way of analysing squid logs in splunk?

Tags (1)
1 Solution

rroberts
Splunk Employee
Splunk Employee

When you set sourcetype to manual you should be able to type squid_access in the box below.

View solution in original post

0 Karma

rroberts
Splunk Employee
Splunk Employee

When you set sourcetype to manual you should be able to type squid_access in the box below.

0 Karma

njathan
Explorer

thanks rroberts 🙂

0 Karma

rroberts
Splunk Employee
Splunk Employee

I see what you mean now have you seen this doc? http://www.splunk.com/wiki/Community:Field_extractions_for_Squid_data
There is a props.conf and transforms.conf example for squid field extraction that might be helpful.

0 Karma

njathan
Explorer

actually manually typing access_squid does not help in that fields like TCP_MISS/200, CONNECT, http://mail.google.com etc in the log dont get classified into separate fields. Tried the 'extract fields' options, but i am poor at regex, and would be helpful if there is a ready plugin that lets splunk categorize the fields accordingly. (Which is not happening right now.)

0 Karma

njathan
Explorer

the 'drop-down' list appears when i choose the 'From list' option in the 'Set sourcetype' section... Manual sourcetype does not give any listing...

0 Karma
Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...