If I would do one long rex for each different type of proxy logs, there would be a lot of work to do. Since you have one long rex which is really specific to that single type of proxy logs, you would need to create tons of them. I was looking for something more general, and wasn't sure how to create it. In my logs, I've been seeing a lot of different field structures. Not sure why.
2016-01-14 00:42:32 284 10.130.16.102 - - proxy.domain.net x.x.x.x None - - PROXIED "Social Networking" http://www.domain.com/article/david-bowie-blackstar-album-sales-networth 200 TCP_NC_MISS GET application/javascript;%20charset=utf-8 http platform.domain.com 80 /widgets.js - js "Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.106 Safari/537.36" 172.16.130.10 27626 726 - "Widgets" - none
OR
2016-01-14 00:42:03 1 10.130.0.156 - - 0.0.0.0 - Invalid - invalid_request PROXIED - - 400 TCP_NC_MISS unknown - - - 0 / - - - 172.16.130.10 842 152 - "none" "none" none
I have plenty of others that don't lay out together. I would work on it and try to figure something out, but if you have any idea how to approach it, I would really appreciate.
... View more