Splunk Search

splunkd_ui_access logs

Abass42
Communicator

Im trying to create some dashboards to make reading _internal logs easier. I'm trying to figure out what all for the fields we are getting in are. This Splunk Doc has the gist of what I am looking at, but we have more fields than that. 

Abass42_0-1722635298465.png

 

In the doc it mentions something about apache and its logs, and whereas we do use apache, im not well versed in it enough to understand what i was looking at fully. I think we are adding in extracted fields, or adding in values in the processing that Splunk does. How can i track down what .conf file is adding the fields. Id like to have a better understanding of where these values come from. There are a lot more fields than the _raw logs seem to have. Like metadata. 

Labels (1)
0 Karma

ITWhisperer
SplunkTrust
SplunkTrust

Which exact fields are you interested in?

0 Karma

yuanliu
SplunkTrust
SplunkTrust

The document is saying that the splunkd_ui_access.log uses the Apache access.log common format.  So, the same extraction is applied.  It is unrelated to your use of Apache httpd.

If you have more fields, you need to illustrate your data and point out where additional information can be extracted.

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...