All Apps and Add-ons

What fields is the Splunk add-on for NetApp supposed to extract from syslog messages?

hettervik
Builder

Hi. The Splunk add-on for NetApp uses a transform to try to extract three fields from syslog; Thread, Event, and Message. The transform is not correct with the syslog I'm receiving, so I'll have to edit the regex manually. When I look at the NetApp documentation I can find no reference to the fields Thread and Event. Rather to me it looks like the extracted fields should be something like Identifier, Severity and Message.

Have a look at the NetApp documentation here: https://library.netapp.com/ecm/ecm_get_file/ecmlp2776519

Can someone explain to me what the three fields Thread, Event and Message should be?

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...