<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic sourcetype cron, cron-2 or syslog in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/sourcetype-cron-cron-2-or-syslog/m-p/493109#M60706</link>
    <description>&lt;P&gt;All,&lt;/P&gt;

&lt;P&gt;I am having issues with all versions of UF.&lt;/P&gt;

&lt;P&gt;I installed Splunk_TA_nix 7.0.0 on some Splunk UF 8.0.2.1 and old Splunk UF 6.2.4&lt;/P&gt;

&lt;P&gt;It has the following stanza in the local/inputs.conf:&lt;/P&gt;

&lt;P&gt;[monitor:///var/log]&lt;BR /&gt;
whitelist=(.log|log$|messages|secure|auth|mesg$|cron$|acpid$|.out)&lt;BR /&gt;
blacklist=(lastlog|anaconda.syslog)disabled = 0&lt;/P&gt;

&lt;P&gt;For some reason I have many different sourcetypes:&lt;/P&gt;

&lt;P&gt;| tstats count where (source=*cron earliest=-4h) by source sourcetype&lt;/P&gt;

&lt;P&gt;source sourcetype   count&lt;BR /&gt;
1   /var/log/cron   cron    40884&lt;BR /&gt;
2   /var/log/cron   cron-2  41597&lt;BR /&gt;
3   /var/log/cron   cron-3  15487&lt;BR /&gt;
4   /var/log/cron   cron-4  3019&lt;BR /&gt;
5   /var/log/cron   cron-5  681&lt;BR /&gt;
6   /var/log/cron   cron-too_small  3192&lt;BR /&gt;
7   /var/log/cron   monolith_tool_usage 169&lt;BR /&gt;
8   /var/log/cron   sendmail_syslog 1732&lt;BR /&gt;
9   /var/log/cron   syslog  58095&lt;/P&gt;

&lt;P&gt;I tried everything to find how this sourcetype is set, I cannot see anything in our indexer of UF props.conf. All the sources in the same stanza have the same issue, but cron is so far the worse.&lt;/P&gt;

&lt;P&gt;Any help will be very appreciated,&lt;/P&gt;

&lt;P&gt;Gerson Garcia&lt;/P&gt;</description>
    <pubDate>Wed, 30 Sep 2020 04:35:28 GMT</pubDate>
    <dc:creator>GersonGarcia</dc:creator>
    <dc:date>2020-09-30T04:35:28Z</dc:date>
    <item>
      <title>sourcetype cron, cron-2 or syslog</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/sourcetype-cron-cron-2-or-syslog/m-p/493109#M60706</link>
      <description>&lt;P&gt;All,&lt;/P&gt;

&lt;P&gt;I am having issues with all versions of UF.&lt;/P&gt;

&lt;P&gt;I installed Splunk_TA_nix 7.0.0 on some Splunk UF 8.0.2.1 and old Splunk UF 6.2.4&lt;/P&gt;

&lt;P&gt;It has the following stanza in the local/inputs.conf:&lt;/P&gt;

&lt;P&gt;[monitor:///var/log]&lt;BR /&gt;
whitelist=(.log|log$|messages|secure|auth|mesg$|cron$|acpid$|.out)&lt;BR /&gt;
blacklist=(lastlog|anaconda.syslog)disabled = 0&lt;/P&gt;

&lt;P&gt;For some reason I have many different sourcetypes:&lt;/P&gt;

&lt;P&gt;| tstats count where (source=*cron earliest=-4h) by source sourcetype&lt;/P&gt;

&lt;P&gt;source sourcetype   count&lt;BR /&gt;
1   /var/log/cron   cron    40884&lt;BR /&gt;
2   /var/log/cron   cron-2  41597&lt;BR /&gt;
3   /var/log/cron   cron-3  15487&lt;BR /&gt;
4   /var/log/cron   cron-4  3019&lt;BR /&gt;
5   /var/log/cron   cron-5  681&lt;BR /&gt;
6   /var/log/cron   cron-too_small  3192&lt;BR /&gt;
7   /var/log/cron   monolith_tool_usage 169&lt;BR /&gt;
8   /var/log/cron   sendmail_syslog 1732&lt;BR /&gt;
9   /var/log/cron   syslog  58095&lt;/P&gt;

&lt;P&gt;I tried everything to find how this sourcetype is set, I cannot see anything in our indexer of UF props.conf. All the sources in the same stanza have the same issue, but cron is so far the worse.&lt;/P&gt;

&lt;P&gt;Any help will be very appreciated,&lt;/P&gt;

&lt;P&gt;Gerson Garcia&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 04:35:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/sourcetype-cron-cron-2-or-syslog/m-p/493109#M60706</guid>
      <dc:creator>GersonGarcia</dc:creator>
      <dc:date>2020-09-30T04:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: sourcetype cron, cron-2 or syslog</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/sourcetype-cron-cron-2-or-syslog/m-p/521607#M63584</link>
      <description>&lt;P&gt;I want to know the answer to this too!&lt;/P&gt;</description>
      <pubDate>Sat, 26 Sep 2020 13:51:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/sourcetype-cron-cron-2-or-syslog/m-p/521607#M63584</guid>
      <dc:creator>esalesap</dc:creator>
      <dc:date>2020-09-26T13:51:53Z</dc:date>
    </item>
    <item>
      <title>Re: sourcetype cron, cron-2 or syslog</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/sourcetype-cron-cron-2-or-syslog/m-p/533344#M64452</link>
      <description>&lt;P&gt;I presume this is coming from the learned app in Splunk. Splunk automatically stores the sourcetype in props.conf if it is not mentioned by default.&lt;/P&gt;&lt;P&gt;Please check if the sourcetype is available in the learned app in both UF &amp;amp; indexer. $SPLUNK_HOME\etc\apps\learned\local\&lt;/P&gt;</description>
      <pubDate>Wed, 16 Dec 2020 17:03:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/sourcetype-cron-cron-2-or-syslog/m-p/533344#M64452</guid>
      <dc:creator>saravanan90</dc:creator>
      <dc:date>2020-12-16T17:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: sourcetype cron, cron-2 or syslog</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/sourcetype-cron-cron-2-or-syslog/m-p/595654#M76722</link>
      <description>&lt;P&gt;I would like to take this moment to say that your best bet is to comment out this entry in the Nix TA until Splunk has a better way to get sourcetypes from linux - cron is a great source of data but it doesn't seem that Splunk cares about making the data actually useful, at least in this instance. If you can create your own sourcetype, you should definitely share it on Github, but other than that, I don't know that we're going to be seeing any tools for this any time soon. There may be a good use case for a supplementary TA that adds onto the linux TA which monitors standard files and assigns/defines the correct sourcetypes for them.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Apr 2022 20:47:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/sourcetype-cron-cron-2-or-syslog/m-p/595654#M76722</guid>
      <dc:creator>haraksin</dc:creator>
      <dc:date>2022-04-27T20:47:55Z</dc:date>
    </item>
  </channel>
</rss>

