Hi to all, excuse if I don't know splunk so well, but I'd like learn it.
I show you my problem:
I have to index the log about mail server, in the log file I have many many information, but I need index only the fiel contain the "LOGIN" "LOGOUT" words, and only for specific file ( mail.log ). Some body can help me, how can I do it?
thanks..
my english is not so good.. :)