Splunk Search

Issue with websphere sourcetype add-on

pdantuuri0411
Explorer

Hi, We recently installed splunk add on for websphere source type "ibm:was:serverIndex" for websphere logs.

When manually adding a log file using add data option, splunk is picking up and setting the sourcetype automatically and extracting all the fields. See [1]

But when configuring inputs.conf file using the same source types, it is failing to extract the fields. See [2]

Please advise on what should be done to auto extract all the fields.

[1]

sourcetypeibm:was:systemOutLog
Eventeventtypeibm_was_errors  
 wasClassNamecom.ibm.ws.webcontainer.internal.WebContainer 
 wasEventLogTypeE 
 wasMessageA WebGroup/Virtual Host to handle / has not been defined. 
 wasMessageIDSRVE0255E 
 wasMethodNamehandleRequest 
 wasShortNameWebContainer 
 wasThreadID00013588 
 was_hostdw07apl43 

 

[2]

sourcetypeibm:was:systemOutLog
Eventappserverserver89-2  
 profileWASFNINT 
 was_hostdw21apl89
Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...