Splunk Search

Issue with websphere sourcetype add-on

pdantuuri0411
Explorer

Hi, We recently installed splunk add on for websphere source type "ibm:was:serverIndex" for websphere logs.

When manually adding a log file using add data option, splunk is picking up and setting the sourcetype automatically and extracting all the fields. See [1]

But when configuring inputs.conf file using the same source types, it is failing to extract the fields. See [2]

Please advise on what should be done to auto extract all the fields.

[1]

sourcetypeibm:was:systemOutLog
Eventeventtypeibm_was_errors  
 wasClassNamecom.ibm.ws.webcontainer.internal.WebContainer 
 wasEventLogTypeE 
 wasMessageA WebGroup/Virtual Host to handle / has not been defined. 
 wasMessageIDSRVE0255E 
 wasMethodNamehandleRequest 
 wasShortNameWebContainer 
 wasThreadID00013588 
 was_hostdw07apl43 

 

[2]

sourcetypeibm:was:systemOutLog
Eventappserverserver89-2  
 profileWASFNINT 
 was_hostdw21apl89
Labels (1)
0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.