Getting Data In

cannot find sourcetype squid

njathan
Explorer

I am trying to analyse a squid access log for top 10 reports (top sources, top destinations, etc.)

I imported the log file in Manager » Data inputs » Files & Directories » Add New

When i keep the sourcetype=automatic, it does not seem to identify the source destination etc fields... just bundles them into one huge field, which is useless.

Elsewhere in this forum, i found someone's using sourcetype=squid_access. Where is this available for the latest version (4.1.4)? If not this, what is the best way of analysing squid logs in splunk?

Tags (1)
1 Solution

rroberts
Splunk Employee
Splunk Employee

When you set sourcetype to manual you should be able to type squid_access in the box below.

View solution in original post

0 Karma

rroberts
Splunk Employee
Splunk Employee

When you set sourcetype to manual you should be able to type squid_access in the box below.

0 Karma

njathan
Explorer

thanks rroberts 🙂

0 Karma

rroberts
Splunk Employee
Splunk Employee

I see what you mean now have you seen this doc? http://www.splunk.com/wiki/Community:Field_extractions_for_Squid_data
There is a props.conf and transforms.conf example for squid field extraction that might be helpful.

0 Karma

njathan
Explorer

actually manually typing access_squid does not help in that fields like TCP_MISS/200, CONNECT, http://mail.google.com etc in the log dont get classified into separate fields. Tried the 'extract fields' options, but i am poor at regex, and would be helpful if there is a ready plugin that lets splunk categorize the fields accordingly. (Which is not happening right now.)

0 Karma

njathan
Explorer

the 'drop-down' list appears when i choose the 'From list' option in the 'Set sourcetype' section... Manual sourcetype does not give any listing...

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...