Hy guys,
I have files in the format access_combined_wcookie, the last field called "other", has informations that are importants for business and us (IT). How to extract the information this field using the format access_combined_wcookie(known by default by splunk) and use regex directly in the files props.conf e transforms.conf ?
Follow one line of the file of the log.
186.241.214.128 - - [28/Nov/2013:02:09:24 +0000] "GET /127.0.0.1/_files/local/defaultTheme/img/image.png HTTP/1.1" 200 3288 "-" "Mozilla/5.0 (Windows NT 6.1; rv:25.0) Gecko/20100101 Firefox/25.0" "-" "other_1234|xxxxxx:xxxxxx|yyyyyy:yyyyyy"
I did this using regex and configuring the props.conf file. After I improved that solution, using data model. If anybody need help about alike situation , please talk to me.
I did this using regex and configuring the props.conf file. After I improved that solution, using data model. If anybody need help about alike situation , please talk to me.