Getting Data In

help on sourcetype parsing

jip31
Motivator

hello

I want to create a new sourcetype from the csv file below
https://www.cjoint.com/c/IHvhvr2JHYh
I dont want to collect the logs between line 1 and line 561 and I just need to collect the logs from line 562
More, I need to create a new field called "flagname" for being able to extract piece of logs like TEST-TOUPDATE.$w$ (in red color in the csv file, line 562)
so what I have exactly to do in advanced parameters to do this??
thanks in advance

0 Karma
1 Solution

jip31
Motivator

It doesnt help me a lot but i am going to find a good way

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...