Hi, We recently installed splunk add on for websphere source type "ibm:was:serverIndex" for websphere logs.
When manually adding a log file using add data option, splunk is picking up and setting the sourcetype automatically and extracting all the fields. See [1]
But when configuring inputs.conf file using the same source types, it is failing to extract the fields. See [2]
Please advise on what should be done to auto extract all the fields.
[1]
sourcetype | ibm:was:systemOutLog |
[2]
sourcetype | ibm:was:systemOutLog |
Event | appserver | server89-2 | ||
profile | WASFNINT | |||
was_host | dw21apl89 |