Good morning. I have a file that looks like this:
2016-05-09 04:36:02,963[qtp789448364-261]|WARN|org.eclipse.jetty.io.nio|71-org.eclipse.jetty.util7.6.8.v20121106|javax.net.ssl.SSLHandshakeException: null cert chain
I need to delimit it by a | and then name the fields, how is this done?
Use this in props.conf:
[YourSourcetypeHere]
INDEXED_EXTRACTIONS = PSV
FIELD_NAMES = MyFieldName1, MyFieldName2, ... , MyFieldNameN
TIMESTAMP_FIELDS = MyFieldName1
Put this on your FORWARDERS and restart all Splunk instances there.
https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf
props.conf:
[sourcetype]
INDEXED_EXTRACTIONS = PSV
FIELD_NAMES = column1, column2, etc
Thank you! The first element is a date, do I skip this element?
no, dont skip it.