Hi
I am splitting my umbrella DNS and proxy logs by sourcetype as per the instructions in the guide (opensdns:dnslogs, opendns:proxy).
However, the field extraction for the proxy logs is not working correctly.
DNS is working great and I can search by category, action, etc but these same field extractions fail for the opendns:proxy sourcetype events.
Am I missing something obvious?
I believe you may be using the incorrect sourcetype. The proxy logs need to use "opendns:proxylogs", it's referenced several times in the README with the proper sourcetype, but I see there is a typo that mentions "opendns:proxy". I will get this corrected in the README (I'm the owner/updater of this app via Hurricane Labs). Thanks for bringing this up!
Updated the sourcetype to the correct format and all working correctly.
Thank you for the quick response!
I believe you may be using the incorrect sourcetype. The proxy logs need to use "opendns:proxylogs", it's referenced several times in the README with the proper sourcetype, but I see there is a typo that mentions "opendns:proxy". I will get this corrected in the README (I'm the owner/updater of this app via Hurricane Labs). Thanks for bringing this up!