Splunk Search

Issue with websphere sourcetype add-on

pdantuuri0411
Explorer

Hi, We recently installed splunk add on for websphere source type "ibm:was:serverIndex" for websphere logs.

When manually adding a log file using add data option, splunk is picking up and setting the sourcetype automatically and extracting all the fields. See [1]

But when configuring inputs.conf file using the same source types, it is failing to extract the fields. See [2]

Please advise on what should be done to auto extract all the fields.

[1]

sourcetypeibm:was:systemOutLog
Eventeventtypeibm_was_errors  
 wasClassNamecom.ibm.ws.webcontainer.internal.WebContainer 
 wasEventLogTypeE 
 wasMessageA WebGroup/Virtual Host to handle / has not been defined. 
 wasMessageIDSRVE0255E 
 wasMethodNamehandleRequest 
 wasShortNameWebContainer 
 wasThreadID00013588 
 was_hostdw07apl43 

 

[2]

sourcetypeibm:was:systemOutLog
Eventappserverserver89-2  
 profileWASFNINT 
 was_hostdw21apl89
Labels (1)
0 Karma
Get Updates on the Splunk Community!

Ready, Set, SOAR: How Utility Apps Can Up Level Your Playbooks!

 WATCH NOW Powering your capabilities has never been so easy with ready-made Splunk® SOAR Utility Apps. Parse ...

DevSecOps: Why You Should Care and How To Get Started

 WATCH NOW In this Tech Talk we will talk about what people mean by DevSecOps and deep dive into the different ...

Introducing Ingest Actions: Filter, Mask, Route, Repeat

WATCH NOW Ingest Actions (IA) is the best new way to easily filter, mask and route your data in Splunk® ...