Knowledge Management

Need assistance mapping fields in a PSV file that has no headers

brent_weaver
Builder

Good morning. I have a file that looks like this:

2016-05-09 04:36:02,963[qtp789448364-261]|WARN|org.eclipse.jetty.io.nio|71-org.eclipse.jetty.util7.6.8.v20121106|javax.net.ssl.SSLHandshakeException: null cert chain

I need to delimit it by a | and then name the fields, how is this done?

Tags (1)
0 Karma

woodcock
Esteemed Legend

Use this in props.conf:

[YourSourcetypeHere]
INDEXED_EXTRACTIONS = PSV
FIELD_NAMES = MyFieldName1, MyFieldName2, ... , MyFieldNameN
TIMESTAMP_FIELDS = MyFieldName1

Put this on your FORWARDERS and restart all Splunk instances there.

0 Karma

jkat54
SplunkTrust
SplunkTrust

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf

props.conf:

[sourcetype]
INDEXED_EXTRACTIONS = PSV
FIELD_NAMES = column1, column2, etc
0 Karma

brent_weaver
Builder

Thank you! The first element is a date, do I skip this element?

0 Karma

jkat54
SplunkTrust
SplunkTrust

no, dont skip it.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...