Splunk Search

Search-time field extraction - Apache access_combined + additional field

johntopley
Explorer

I have a custom log format that is Apache's access_combined format with a custom field representing an app's version number at the end. The fields are space separated. How can I configure Splunk to do automatic search-time field extraction of the standard access_combined set of fields and this extra field?

0 Karma
1 Solution

lguinn2
Legend

You have two choices:

  1. Assign the source type of access_combined and in props.conf, add a field for the version number. (An example of the field extraction is below.) This should work even if you have other logs that are the "standard" access_combined format, since the field won't be extracted where it doesn't exist.
  2. Find the definition of access_combined in the default props.conf and copy it to your own props.conf, giving the stanza a different name. Then add the app version field.

Here is the field extraction for the the new field, which I call app_version (because the Apache logs already have a field named version which is the Apache version).

EXTRACT-e1 = \s(?<app_version>\S+)\s*$

This field will contain the last non-blank character string on the line.

View solution in original post

lguinn2
Legend

You have two choices:

  1. Assign the source type of access_combined and in props.conf, add a field for the version number. (An example of the field extraction is below.) This should work even if you have other logs that are the "standard" access_combined format, since the field won't be extracted where it doesn't exist.
  2. Find the definition of access_combined in the default props.conf and copy it to your own props.conf, giving the stanza a different name. Then add the app version field.

Here is the field extraction for the the new field, which I call app_version (because the Apache logs already have a field named version which is the Apache version).

EXTRACT-e1 = \s(?<app_version>\S+)\s*$

This field will contain the last non-blank character string on the line.

Get Updates on the Splunk Community!

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to ...

Announcing the Migration of the Splunk Add-on for Microsoft Azure Inputs to Officially Supported Splunk ...