<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: props.conf cant figure source in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/props-conf-cant-figure-source/m-p/73810#M8829</link>
    <description>&lt;P&gt;The easiest way to do it would be to specify a sourcetype name in inputs.conf on your lightweight forwarder. Just add sourcetype=myshellstuff to the stanza you're using for watching this particular data. Then you can change ['what do i set here?'] to [myshellstuff].&lt;/P&gt;

&lt;P&gt;['what do i set here?'] can be lots of stuff though. Check out &lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Propsconf" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/Admin/Propsconf&lt;/A&gt; for more info; specifically the section on about []. It's right at the top, and it has a list of all the stuff  can be.&lt;/P&gt;</description>
    <pubDate>Wed, 20 Oct 2010 22:48:14 GMT</pubDate>
    <dc:creator>CarlS</dc:creator>
    <dc:date>2010-10-20T22:48:14Z</dc:date>
    <item>
      <title>props.conf cant figure source</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/props-conf-cant-figure-source/m-p/73809#M8828</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I have enabled content based routing in my environment; consisting of a &lt;STRONG&gt;lightweight forwarder (A)&lt;/STRONG&gt; &amp;amp; a &lt;STRONG&gt;splunk server (B).&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;I have set REGEX on server side (B) to filter out logs I dont want from a file monitored on A. I want to filter out events that match my REGEX &amp;amp; index them to index sis &amp;amp; drop events that dont match by sending them to nullQueue.&lt;/P&gt;

&lt;P&gt;Also I guess since I already mentioned index in transforms.conf I dont need to configure anything in outputs.conf&lt;/P&gt;

&lt;P&gt;However i cant seem to figure out what to set as source i.e  in props.conf&lt;/P&gt;

&lt;P&gt;I have set the receiver on B as 8001. i.e. splunkserver:8001 How do I set this in my props.conf??&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;props.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;['what do i set here?']&lt;/P&gt;

&lt;P&gt;TRANSFORMS-routing3 = shell,others&lt;/P&gt;

&lt;P&gt;&lt;/P&gt;&lt;HR /&gt;&lt;P&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;transforms.conf&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;[shell]&lt;/P&gt;

&lt;P&gt;REGEX= .*([Ss][Ii])&lt;/P&gt;

&lt;P&gt;DEST_KEY=_MetaData:Index&lt;/P&gt;

&lt;P&gt;FORMAT= sis&lt;/P&gt;

&lt;P&gt;[others]&lt;/P&gt;

&lt;P&gt;REGEX=^((?![Ss][Ii])).)*$ &lt;/P&gt;

&lt;P&gt;DEST_KEY=queue&lt;/P&gt;

&lt;P&gt;FORMAT=nullQueue&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2010 22:13:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/props-conf-cant-figure-source/m-p/73809#M8828</guid>
      <dc:creator>standias</dc:creator>
      <dc:date>2010-10-20T22:13:56Z</dc:date>
    </item>
    <item>
      <title>Re: props.conf cant figure source</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/props-conf-cant-figure-source/m-p/73810#M8829</link>
      <description>&lt;P&gt;The easiest way to do it would be to specify a sourcetype name in inputs.conf on your lightweight forwarder. Just add sourcetype=myshellstuff to the stanza you're using for watching this particular data. Then you can change ['what do i set here?'] to [myshellstuff].&lt;/P&gt;

&lt;P&gt;['what do i set here?'] can be lots of stuff though. Check out &lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Propsconf" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/Admin/Propsconf&lt;/A&gt; for more info; specifically the section on about []. It's right at the top, and it has a list of all the stuff  can be.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Oct 2010 22:48:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/props-conf-cant-figure-source/m-p/73810#M8829</guid>
      <dc:creator>CarlS</dc:creator>
      <dc:date>2010-10-20T22:48:14Z</dc:date>
    </item>
    <item>
      <title>Re: props.conf cant figure source</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/props-conf-cant-figure-source/m-p/73811#M8830</link>
      <description>&lt;P&gt;For reference :&lt;/P&gt;

&lt;P&gt;====inputs.conf on LightWeight Forwarder side:&lt;/P&gt;

&lt;P&gt;[monitor://D:\LOGS\Sis102010.txt ]
sourcetype= src_Si &lt;/P&gt;

&lt;P&gt;====props.conf on Indexer side: &lt;/P&gt;

&lt;P&gt;[src_Si]&lt;/P&gt;

&lt;P&gt;TRANSFORMS-routing3 = shell,others&lt;/P&gt;

&lt;P&gt;====transforms.conf &lt;/P&gt;

&lt;P&gt;Same as before&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2010 18:39:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/props-conf-cant-figure-source/m-p/73811#M8830</guid>
      <dc:creator>standias</dc:creator>
      <dc:date>2010-10-22T18:39:49Z</dc:date>
    </item>
    <item>
      <title>Re: props.conf cant figure source</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/props-conf-cant-figure-source/m-p/73812#M8831</link>
      <description>&lt;P&gt;Solved!! Thanks CarlS &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Oct 2010 18:40:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/props-conf-cant-figure-source/m-p/73812#M8831</guid>
      <dc:creator>standias</dc:creator>
      <dc:date>2010-10-22T18:40:54Z</dc:date>
    </item>
  </channel>
</rss>

