All Apps and Add-ons

Field Extractions for IAS app

gregwilliams
Path Finder

Since I don't see much documentation for this app, what needs to be set in order for the lookups to happen? Do I need to change sourcetype, source?

0 Karma

southeringtonp
Motivator

The main thing is to make sure your sourcetype is set to ias.

0 Karma

southeringtonp
Motivator

Not sure I follow. Are you expecting to see a difference in the log entries themselves? The lookup values appear as new extracted fields, so you should start to see them in the field picker at the left. You might need to click pick fields to bring up the full list.

0 Karma

gregwilliams
Path Finder

got it. I still see default logs however. Do I need to put something else in my search string except for sourcetype=ias?

0 Karma

sdaniels
Splunk Employee
Splunk Employee
0 Karma
Get Updates on the Splunk Community!

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...