Splunk Search

Field extraction on source type

indeed_2000
Motivator

on splunk when i want to do field extraction ask me source type. and when I open this listbox show files on that path as source.

Here is the logs “/opt/logs”
On this path there are some other files that have different structure! For example config file, database export, ...

While when I import data also create specific new index for it, but this index not show on source type listbox.

Now i need to do field extraction on several log file that exist on that path.

Any recommendation?
Thanks

Thanks

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar - Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...