Splunk Search

Issue with websphere sourcetype add-on

pdantuuri0411
Explorer

Hi, We recently installed splunk add on for websphere source type "ibm:was:serverIndex" for websphere logs.

When manually adding a log file using add data option, splunk is picking up and setting the sourcetype automatically and extracting all the fields. See [1]

But when configuring inputs.conf file using the same source types, it is failing to extract the fields. See [2]

Please advise on what should be done to auto extract all the fields.

[1]

sourcetypeibm:was:systemOutLog
Eventeventtypeibm_was_errors  
 wasClassNamecom.ibm.ws.webcontainer.internal.WebContainer 
 wasEventLogTypeE 
 wasMessageA WebGroup/Virtual Host to handle / has not been defined. 
 wasMessageIDSRVE0255E 
 wasMethodNamehandleRequest 
 wasShortNameWebContainer 
 wasThreadID00013588 
 was_hostdw07apl43 

 

[2]

sourcetypeibm:was:systemOutLog
Eventappserverserver89-2  
 profileWASFNINT 
 was_hostdw21apl89
Labels (1)
0 Karma
Get Updates on the Splunk Community!

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...

SignalFlow: What? Why? How?

What is SignalFlow? Splunk Observability Cloud’s analytics engine, SignalFlow, opens up a world of in-depth ...

Federated Search for Amazon S3 | Key Use Cases to Streamline Compliance Workflows

Modern business operations are supported by data compliance. As regulations evolve, organizations must ...