Hi all,
I recently had the Translatefix app installed in my company's Splunk environment and it is working great, many thanks to Glenn for creating it! http://splunk-base.splunk.com/apps/22347/financial-information-exchange-fix-log-parsing
One question I have, is that when I take my FIX logs and pipe them to translatefix, the logs are transformed successfully into "plain english" fields, but Splunk never seems to auto-extract them so I can work with them (or it extracts some but not others). Is there anything I might be able to do to make this happen. Example of a translated log:
2013-05-22 12:55:04,078 INFO in.test_test1 - <10781 ExecutionReport (8=FIX.4.2 BodyLength=295 MsgType=Execution Report TargetSubID=ABC 129=123 TargetCompID=TESTCOMP SenderCompID=TESTCOMP2 SendingTime=20130522-16:55:04 MsgSeqNum=10781 TradeDate=20130522 OrderID=abc_123_456 ClOrdID=1234567890-1 ExecID=abc_2456435_123456 ExecTransType=New OrdStatus=Canceled Account=00000123 Symbol=TESTSYMBOL Side=2 OrderQty=1000 OrdType=Limit Price=8.50 TimeInForce=Day LastShares=0 LastPx=0.00 CumQty=400 AvgPx=8.499 TransactTime=20130522-16:55:04 OrigClOrdID=1234567890-0 ExecType=Canceled LeavesQty=0 CheckSum=092 )
Everything seems clearly seperated so I am not sure why Splunk is not automatically extracting any of the created fields. Any thoughts as to how I can make this happen?
... View more