Splunk Inc.
HTTP events with custom fields

Last updated:

Abstract:

A data intake and query system receives a message including raw machine via an internet protocol (IP) such as the hypertext transfer protocol (HTTP). The message includes a distinct payload portion and a distinct custom field portion. The payload portion includes raw machine data, while the custom field portion includes values for fields. An event that includes the raw machine data and the values is generated from the payload portion and the values are extracted from the custom field portion. The event is then stored such that the values are associated with the event.

Status:
Grant
Type:

Utility

Filling date:

26 Sep 2016

Issue date:

17 Aug 2021