The venerable old-skool Splunk forums are now closed. Feel free to search for old content here, but new posts are no longer supported.

Instead, please visit the thriving community at answers.splunk.com to ask and answer questions about your Splunk deployment and how to get the most out of it.

Forums: SplunkPreview: index only specific field from log file

Next Topic: Splunk queries do not return data in the dashboard


Posts 1–1 of 1

Hi to all, excuse if I don't know splunk so well, but I'd like learn it.

I show you my problem:

I have to index the log about mail server, in the log file I have many many information, but I need index only the fiel contain the "LOGIN" "LOGOUT" words, and only for specific file ( mail.log ). Some body can help me, how can I do it?

thanks..
my english is not so good.. :)