Extract Individual Fields from Audit Log

Strickland, David R dstrickland at austin.utexas.edu
Thu Mar 16 19:32:12 EDT 2017


Hi all,

 

I would like to add some tags to the fields logged in the audit log, eg:

 

requestBinding=urn:oasis:names:tc:SAML:2.0:bindings:HTTP-Redirect
relyingPartyId=https://utlr-q01-sp.its.utexas.edu/shibboleth
principalName=drs2295 .

 

I know the format of %msg (available in logback.xml) is hard-coded, but is
there any way I can get to these fields individually, perhaps with a custom
field extraction bean?

 

My use-case is that our Splunk service automatically indexes fields with the
name=value syntax. While I can have Splunk extract these fields with a
regular expression, it can get pretty expensive to run those searches.

 

Thanks in advance,

David

 

David Strickland

Lead Software Engineer

Identity and Access Management

The University of Texas at Austin

512-232-2974

 

-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://shibboleth.net/pipermail/users/attachments/20170316/f9ef4f7d/attachment.html>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: smime.p7s
Type: application/pkcs7-signature
Size: 6162 bytes
Desc: not available
URL: <http://shibboleth.net/pipermail/users/attachments/20170316/f9ef4f7d/attachment.p7s>


More information about the users mailing list