I'm having trouble understanding how to create customer fields for my application logs. My logs have the following fields:
Timestamp SourceIP Token HTTP.Method URL Query.String Post.Data U...
“CreateSourceType” inquiry.
We want to create a new sourcetype that break events based a word orderActivityRep { and the event ends with }.
How to do it
The logs arrive to Splunk in t...
I'm trying to create a custom sourcetype which is reading a TSV log file and the 3 column in the file is a JSON payload wrapped in quotes. I can't figure out how to get the sourcetype to parse o...
...ometime that xyz.ps1 gets stuck into weird state and we didnt see message in last 60 minutes for some hosts. I was able to create alert where i get list of hosts which shows that message. But I am e...
Hello,
I know we can use SPLUNK GUI to createsourcetypes. But how I would create a new sourcetype from CLI or using props.conf file. Any help will be highly appreciated, thank you.
Does this p...
An example of the file is below. I want to break on <Object> and I tried (\<Object>\) and (\<Object\s) with no success. Can someone offer some advice or something to try? <Objects&...
hi all,
I am trying to create a dropdown with 3 different sourcetypes to display a graph per sourcetype.
If I try to change the sourcetype, the graph doesn't show up.
Hi there,
I've been trying to create a new sourcetype, but unfortunately - with no success.
My data is uploaded from a CSV file (hold your horses, there's a small catch).
I put all of the r...
Community, need some help to work with 2 different sourcetypes .
I'm trying to run a search where I need to match information from 2 sources in 1 table.
What I'm trying to do is:
index=u...
....html
I take in one file with multiple JSON and splits it into multiple sourcetypes.
However i have a sub issue, one of the sourcetypes is like below Text + JSON trace.
2018-01-10 15:52:0...