I'm new to the splunk technology, so there have been a few things that I'm stuck with. I have a log format with a field that includes a binary number, so either a single 0 or 1 digit. I'm trying to extract a new field to name this field accordingly, but splunk is having a hard time parsing and identifying this field correctly. I provide a few examples but it only recognizes the zeros in the date field... anyone know what I could do to get it to identify this specific field? Thank you!!
asked 19 Jun '12, 14:35
Is it possible to convert those binary bits to ascii before Splunk indexes it? If so, that would be the route I would go.
answered 19 Jun '12, 19:39