“CreateSourceType” inquiry.
We want to create a new sourcetype that break events based a word orderActivityRep { and the event ends with }.
How to do it
The logs arrive to Splunk in t...
I'm having trouble understanding how to create customer fields for my application logs. My logs have the following fields:
Timestamp SourceIP Token HTTP.Method URL Query.String Post.Data U...
I'm trying to create a custom sourcetype which is reading a TSV log file and the 3 column in the file is a JSON payload wrapped in quotes. I can't figure out how to get the sourcetype to parse o...
hi all,
I am trying to create a dropdown with 3 different sourcetypes to display a graph per sourcetype.
If I try to change the sourcetype, the graph doesn't show up.
Community, need some help to work with 2 different sourcetypes .
I'm trying to run a search where I need to match information from 2 sources in 1 table.
What I'm trying to do is:
index=u...
....html
I take in one file with multiple JSON and splits it into multiple sourcetypes.
However i have a sub issue, one of the sourcetypes is like below Text + JSON trace.
2018-01-10 15:52:0...
Hi there,
I've been trying to create a new sourcetype, but unfortunately - with no success.
My data is uploaded from a CSV file (hold your horses, there's a small catch).
I put all of the r...
I am ingesting 1 file that has multiple server IP addresses. I need to sourcetype each server based on the IP address. I have tried using the props.conf and transforms.conf with no luck. Any help w...
I want to create an alert that triggers when a sourcetype doesn't exist in a lookup table (e.g. srctype.csv). But I'm not sure how to create the search string for this. The fields I'm using in the s...
...imezone fixes this problem but I would rather keep it.
What would be the best way to proceed?
Modify the syslog sourcetype?
Create a new sourcetype?
Report the issue and hope for a fix?