Hi, I have a sever with splunk enterprise installed to monitor a directory containing <sample-filename>.gz files Each file is of the below format and need to create a sourcetype that can 1. Ignore lines staring with // 2. Map the vales in [ ] to a standard header ---------------------------------------------------- [1599249608,75972,"sample@user.ca",638744076,1,861,337,3,"9","http",80,388951746,"http://abc.com",0,"","","","empty","Sample Filtering","","ctldl.windowsupdate.com","GET",21,3,126] // random info here // something something random ------------------------------------------------------- Tried various strategies but filed. Looking for you help.
... View more