props.conf:
[source::/logs/firewall/...]
sourcetype = cisco_syslog
[source::/logs/web/...]
sourcetype = iis
[new-iis]
REPORT-manual-iis = manual-iis
[source::/logs/web/ex140401.log]
sourcetype = iis
transforms.conf:
[manual-iis]
FIELDS = date, time, s-sitename, s-ip, cs-method, cs-uri-stem, cs-uri-query, s-port, cs-username, c-ip, cs-user-agent, sc-status, sc-substatus, sc-win32-status
DELIMS = "\t"
(I tried with DELIMS = " " as well)
Still not parsing. Anything to be gleaned from the search log?
... View more