Splunk Search

Issue with websphere sourcetype add-on

pdantuuri0411
Explorer

Hi, We recently installed splunk add on for websphere source type "ibm:was:serverIndex" for websphere logs.

When manually adding a log file using add data option, splunk is picking up and setting the sourcetype automatically and extracting all the fields. See [1]

But when configuring inputs.conf file using the same source types, it is failing to extract the fields. See [2]

Please advise on what should be done to auto extract all the fields.

[1]

sourcetypeibm:was:systemOutLog
Eventeventtypeibm_was_errors  
 wasClassNamecom.ibm.ws.webcontainer.internal.WebContainer 
 wasEventLogTypeE 
 wasMessageA WebGroup/Virtual Host to handle / has not been defined. 
 wasMessageIDSRVE0255E 
 wasMethodNamehandleRequest 
 wasShortNameWebContainer 
 wasThreadID00013588 
 was_hostdw07apl43 

 

[2]

sourcetypeibm:was:systemOutLog
Eventappserverserver89-2  
 profileWASFNINT 
 was_hostdw21apl89
Labels (1)
0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...