I am using Splunk version 6.0.2-196940
When I add a local file source /var/log/squid3/access.log
I don't see any option of selecting squid as source type. Automatic source type detection is also failing.
I also installed Splunk Weblog Add-on
and Splunk for Squid
apps but still can't find source type for squid.
How do I go about solving this?
Use the "manual" option where you choose sourcetype in the web interface and specify "squid" yourself.