How would I write the props config file for following events, any help will be highly appreciated, thank you!
Thu, 01 Jul 2021 00:20:04 -0400|system|flush_vulns|INFO|-1|Removing old data in Repository
Thu, 01 Jul 2021 00:20:04 -0400|system|flush_vulns|INFO|-1|Successful removal of old data in Repository
Thu, 01 Jul 2021 00:20:05 -0400|system|flush_vulns|INFO|-1|Removing old data in Repository
Thu, 01 Jul 2021 00:20:05 -0400|system|flush_vulns|INFO|-1|Successful removal of old data in Repository
hi @SplunkDash,
You have pipe-separated data, you can also try INDEXED_EXTRACTIONS.
[sourcetype]
INDEXED_EXTRACTIONS = PSV
FIELD_NAMES = timestamp,context,type,log_level,code,message
TIMESTAMP_FIELDS = timestamp
SHOULD_LINEMERGE = false
hi @SplunkDash,
You have pipe-separated data, you can also try INDEXED_EXTRACTIONS.
[sourcetype]
INDEXED_EXTRACTIONS = PSV
FIELD_NAMES = timestamp,context,type,log_level,code,message
TIMESTAMP_FIELDS = timestamp
SHOULD_LINEMERGE = false
..yes working as expected.....thank you so much, truly appreciated!!!
.... yes working as expected. Thank you, truly appreciated.
Hi
can you describe what you want to get by props (e.g. some fields defined or drop events or ....)?
r. Ismo
Thank you so much. I stuck writing my TIME_PREFIX and TIME_FORMAT in Props Configuration file for those events . Thank you again.
Can you post your current version?
7.3.3
Why we need the version of it...? .....anyways, I solved that issue (see below). Thank you so much, appreciated!!!
SHOULD_LINEMERGE=false
LINE_BREAKER=([\r\n]+)
NO_BINARY_CHECK=true
TIME_PREFIX=\,+\s
TIME_FORMAT=%d %b %Y %H:%M:%S %z
MAX_TIMESTAMP_LOOKAHEAD=26