All Apps and Add-ons

How to add custom events to log data while searching for a log(With out mentioning it in the search)

pdantuuri0411
Explorer

How do I add custom events like loglevel that is mentioned in the log to be in an event so it can be categorized by choosing them. For example can I customize a field called loglevel where the type of loglevel can be filtered out?

.alt text

0 Karma

zonistj
Path Finder

It sounds like you want to do a field extraction for the log level. You can do this through the user interface by dropping down "Settings" then going to "Fields" then going to "Field Extractions" and using the wizard to create the extraction.

You can also do this through the props.conf file directly if you're familiar with that syntax.

https://docs.splunk.com/Documentation/Splunk/7.2.3/Knowledge/ExtractfieldsinteractivelywithIFX

https://docs.splunk.com/Splexicon:Fieldextraction

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...