Refine your search:

I want to extract fields from WebLogic logs to use in reports.

asked 20 Oct '10, 14:53

Rob%20Jordan's gravatar image

Rob Jordan
5316
accept rate: 66%


2 Answers:
link

answered 10 Feb '11, 19:27

Ron%20Naken's gravatar image

Ron Naken
3.0k320
accept rate: 35%

  1. In the splunk console, goto Manager --> Fields --> Fields --> Field extractions

  2. Click New

  3. Fill in the form for a new field extraction (you can use the examples I will provide below)

    • Destination app: search
    • Name: Enter a descriptive name for the field you are extracting here
    • Apply to: host named: *
    • Type: Inline
    • Extraction/Transform: Enter your regex for field extraction here
  4. Click Save

Note: If you are familiar with Splunk, you can tweak the Apply to filter to your liking.

You will now see additional fields available on the left whenever a search matches the regex pattern you entered and can start using these in graphs and reports.

Below are templates for step 3 to help get you started. These are working for me with WebLogic 10.3 logs.

  • Destination app: search
  • Name: BEA Info
  • Apply to: host named: *
  • Type: Inline
  • Extraction/Transform: T>\s<(?P<BEA_LOG_LEVEL>\w*)>\s<(?P<BEA_MSG_TYPE>\w*)>\s<(?P<BEA_MACHINE>\w*)>\s<(?P<BEA_SERVER>\w*)>

  • Destination app: search

  • Name: BEA Code
  • Apply to: host named: *
  • Type: Inline
  • Extraction/Transform: <(?P<BEA_CODE>BEA-\d\d\d\d\d\d)>

  • Destination app: search

  • Name: BEA Server State
  • Apply to: host named: *
  • Type: Inline
  • Extraction/Transform: (?P<BEA_SERVER_STATE>\w*)>

  • Destination app: search

  • Name: Java Lang
  • Apply to: host named: *
  • Type: Inline
  • Extraction/Transform: java\.lang\.(?P<JAVA_LANG>\w*)

  • Destination app: search

  • Name: Oracle Code
  • Apply to: host named: *
  • Type: Inline
  • Extraction/Transform: (?P<ORACLE_CODE>ORA-\d\d\d\d\d)

Rob

link

answered 20 Oct '10, 14:55

Rob%20Jordan's gravatar image

Rob Jordan
5316
accept rate: 66%

Post your answer
toggle preview

Follow this question

Log In to enable email subscriptions

RSS:

Answers

Answers + Comments

Markdown Basics

  • *italic* or _italic_
  • **bold** or __bold__
  • link:[text](http://url.com/ "Title")
  • image?![alt text](/path/img.jpg "Title")
  • numbered list: 1. Foo 2. Bar
  • to add a line break simply add two spaces to where you would like the new line to be.
  • basic HTML tags are also supported

Tags:

×354
×130
×32
×19
×5

Asked: 20 Oct '10, 14:53

Seen: 1,846 times

Last updated: 25 Mar '11, 05:22

Copyright © 2005-2012 Splunk, Inc. All rights reserved.