Knowledge Management

Need assistance mapping fields in a PSV file that has no headers

brent_weaver
Builder

Good morning. I have a file that looks like this:

2016-05-09 04:36:02,963[qtp789448364-261]|WARN|org.eclipse.jetty.io.nio|71-org.eclipse.jetty.util7.6.8.v20121106|javax.net.ssl.SSLHandshakeException: null cert chain

I need to delimit it by a | and then name the fields, how is this done?

Tags (1)
0 Karma

woodcock
Esteemed Legend

Use this in props.conf:

[YourSourcetypeHere]
INDEXED_EXTRACTIONS = PSV
FIELD_NAMES = MyFieldName1, MyFieldName2, ... , MyFieldNameN
TIMESTAMP_FIELDS = MyFieldName1

Put this on your FORWARDERS and restart all Splunk instances there.

0 Karma

jkat54
SplunkTrust
SplunkTrust

https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf

props.conf:

[sourcetype]
INDEXED_EXTRACTIONS = PSV
FIELD_NAMES = column1, column2, etc
0 Karma

brent_weaver
Builder

Thank you! The first element is a date, do I skip this element?

0 Karma

jkat54
SplunkTrust
SplunkTrust

no, dont skip it.

0 Karma
Get Updates on the Splunk Community!

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

🔐 Trust at Every Hop: How mTLS in Splunk Enterprise 10.0 Makes Security Simpler

From Idea to Implementation: Why Splunk Built mTLS into Splunk Enterprise 10.0  mTLS wasn’t just a checkbox ...