Knowledge Management

Need assistance mapping fields in a PSV file that has no headers

brent_weaver
Builder

Good morning. I have a file that looks like this:

2016-05-09 04:36:02,963[qtp789448364-261]|WARN|org.eclipse.jetty.io.nio|71-org.eclipse.jetty.util7.6.8.v20121106|javax.net.ssl.SSLHandshakeException: null cert chain

I need to delimit it by a | and then name the fields, how is this done?

Tags (1)
0 Karma

woodcock
Esteemed Legend

Use this in props.conf:

[YourSourcetypeHere]
INDEXED_EXTRACTIONS = PSV
FIELD_NAMES = MyFieldName1, MyFieldName2, ... , MyFieldNameN
TIMESTAMP_FIELDS = MyFieldName1

Put this on your FORWARDERS and restart all Splunk instances there.

0 Karma

jkat54
SplunkTrust
SplunkTrust

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf

props.conf:

[sourcetype]
INDEXED_EXTRACTIONS = PSV
FIELD_NAMES = column1, column2, etc
0 Karma

brent_weaver
Builder

Thank you! The first element is a date, do I skip this element?

0 Karma

jkat54
SplunkTrust
SplunkTrust

no, dont skip it.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...