Getting Data In

how to identify sourcetype forbetter parsing

krutika_ag
Path Finder

I need help in understanding that what sourcetype would be ideal to parse logs of this File type

krutika_ag_1-1710342055829.png

 

Tags (3)
0 Karma

isoutamo
SplunkTrust
SplunkTrust
Hi
Usually you will get some hints about product by looking the directory hierarchy and names on it.
r. Ismo
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @krutika_ag,

you should know where these logs come from, or at least what system produced them.

If not, you could try using the Splunk automatic recognition but I don't like this solution because the error margin is very large.

You could open the files and take some strings to search on internet what could be the technologu that produced them and then you could search the relative sourcetype.

Ciao.

Giuseppe

0 Karma
Get Updates on the Splunk Community!

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Shape the Future of Splunk: Join the Product Research Lab!

Join the Splunk Product Research Lab and connect with us in the Slack channel #product-research-lab to get ...