<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Possible to rewrite the sourcetype twice? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Possible-to-rewrite-the-sourcetype-twice/m-p/614538#M106337</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Why you don't use syslog to write VMware logs to own log files and then put those sourcetype and index into inputs.conf? Then you don't need that second transforms here.&lt;/P&gt;&lt;P&gt;One event can go trough parsing phase only once. If you want send it again to that you should use CLONE_SOURCETYPE for that and then drop all events from old one or you have duplicate events with two different source types.&lt;/P&gt;&lt;P&gt;See dataflow here:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Diagrams-of-how-indexing-works-in-the-Splunk-platform-the-Masa/m-p/590781/highlight/true#M103485" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Diagrams-of-how-indexing-works-in-the-Splunk-platform-the-Masa/m-p/590781/highlight/true#M103485&lt;/A&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Mon, 26 Sep 2022 11:56:02 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2022-09-26T11:56:02Z</dc:date>
    <item>
      <title>Possible to rewrite the sourcetype twice?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Possible-to-rewrite-the-sourcetype-twice/m-p/614533#M106335</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I am trying to get the &lt;A href="https://splunkbase.splunk.com/app/5603/" target="_self"&gt;Splunk_TA_esxilogs&lt;/A&gt; app to work in our Splunk Enviroment, but cant get it working together with our app that rewrites index and sourcetype. I suspect that one Splunk Enterprice instance cannot rewrite the sourcetype and index more that one time.&lt;BR /&gt;&lt;BR /&gt;The ESXi logs are allready collected at an syslog server, and forwarded to the Heavy Forwarder.&lt;BR /&gt;&lt;BR /&gt;At the HF we use "rewrite app" with an regex to change the sourcetype from "syslog" to "esxi", based out of the hostname, like this:&lt;BR /&gt;&lt;BR /&gt;&lt;STRONG&gt;props.conf:&lt;/STRONG&gt;&lt;BR /&gt;&lt;EM&gt;[syslog]&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;TRANSFORMS-force_vmware = force_sourcetype_vmware, force_ix_vmware&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;transforms.conf:&lt;BR /&gt;&lt;/STRONG&gt;&lt;EM&gt;[force_sourcetype_vmware]&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;SOURCE_KEY = MetaData:Host&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;REGEX = ^host::(10\.24[1289]\.70\.\d+|10\.243\.12\.\d+|10\.25[01]\.70\.\d+|10\.252\.198\.50|10\.30\.209\.19[5-6]|10\.36\.1[128]\.\d+|10\.37\.12\.\d+|10\.45\.[12]\.\d+|10\.6[23]\.12.\d+|10\.63\.10\.20|10\.65\.(0|64)\.\d+|10\.65\.65\.65)&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;DEST_KEY = MetaData:Sourcetype&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;FORMAT = sourcetype::vmw-syslog&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;EM&gt;[force_ix_vmware]&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;SOURCE_KEY = MetaData:Sourcetype&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;REGEX = ^sourcetype::(?i)vmw-syslog$&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;DEST_KEY = _MetaData:Index&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;FORMAT = vmware-esxilog&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;So far, so good. This rewrite app does its job. The data now has index "vmware-esxilog" and sourcetype "&lt;EM&gt;vmw-syslog&lt;/EM&gt;".&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Now the Splunk_TA_esxilog app should in theory start baking the data:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;props.conf:&lt;BR /&gt;&lt;/STRONG&gt;&lt;EM&gt;####### INDEX TIME EXTRACTION ##########&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;[vmw-syslog]&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;SHOULD_LINEMERGE = false&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;LINE_BREAKER = ([\r\n]+)(?:.*?(?:[\d\-]{10}T[\d\:]{8}(?:\.\d+)?(?:Z|[\+\-][\d\:]{5})?)\s[^ ]+\s+[^ ]+\s+[^\-&amp;gt;])|([\r\n]+)(?:.*?\w+\s+\d+\s+\d{2}:\d{2}:\d{2})(?:\s+[^ ]+\s+)+[^\-&amp;gt;]&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;TZ = UTC&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;DATETIME_CONFIG = /etc/apps/Splunk_TA_esxilogs/default/syslog_datetime.xml&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;TRANSFORMS-nullqueue = vmware_generic_level_null&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;TRANSFORMS-vmsyslogsourcetype = set_syslog_sourcetype,set_syslog_sourcetype_4x,set_syslog_sourcetype_sections&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;TRANSFORMS-vmsyslogsource = set_syslog_source&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But it doesnt. The data gets indexed without beeing touched by the Splunk_TA_esxilogs app.&lt;/P&gt;&lt;P&gt;It works IF i disable the HF rewrite app, and change the stanza in Splunk_TA_esxilogs from &lt;EM&gt;[vmw-syslog]&lt;/EM&gt; to &lt;EM&gt;[syslog], &lt;/EM&gt;but that will hit way to wide.&lt;/P&gt;&lt;P&gt;The name of the HF rewrite app starts with "05", so its configuration comes before the app named "Splunk_TA_esxilogs".&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Any suggestions is highly appreciated &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 11:24:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Possible-to-rewrite-the-sourcetype-twice/m-p/614533#M106335</guid>
      <dc:creator>Fonzie2k</dc:creator>
      <dc:date>2022-09-26T11:24:46Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to rewrite the sourcetype twice?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Possible-to-rewrite-the-sourcetype-twice/m-p/614538#M106337</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Why you don't use syslog to write VMware logs to own log files and then put those sourcetype and index into inputs.conf? Then you don't need that second transforms here.&lt;/P&gt;&lt;P&gt;One event can go trough parsing phase only once. If you want send it again to that you should use CLONE_SOURCETYPE for that and then drop all events from old one or you have duplicate events with two different source types.&lt;/P&gt;&lt;P&gt;See dataflow here:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Diagrams-of-how-indexing-works-in-the-Splunk-platform-the-Masa/m-p/590781/highlight/true#M103485" target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Diagrams-of-how-indexing-works-in-the-Splunk-platform-the-Masa/m-p/590781/highlight/true#M103485&lt;/A&gt;&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 11:56:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Possible-to-rewrite-the-sourcetype-twice/m-p/614538#M106337</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-09-26T11:56:02Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to rewrite the sourcetype twice?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Possible-to-rewrite-the-sourcetype-twice/m-p/614549#M106338</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;How exactly could that be done?&lt;BR /&gt;&lt;BR /&gt;I would need a [monitor://] stanza for each ESXi host, and we have hundereds. Thats why we define the esxi hosts with regrex, in the HF rewrite app.&lt;BR /&gt;&lt;BR /&gt;If we had just a few, it could be solved by the following in inputs.conf:&lt;BR /&gt;&lt;EM&gt;[monitor:///data/logs/esxihost1]&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;disabled = false&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;host_segment = 3&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sourcetype = vmw-syslog&lt;/EM&gt;&lt;BR /&gt;&lt;BR /&gt;Was this your suggestion, or did i misunderstand?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 12:37:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Possible-to-rewrite-the-sourcetype-twice/m-p/614549#M106338</guid>
      <dc:creator>Fonzie2k</dc:creator>
      <dc:date>2022-09-26T12:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to rewrite the sourcetype twice?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Possible-to-rewrite-the-sourcetype-twice/m-p/614557#M106340</link>
      <description>&lt;P&gt;Thanks anyways. My &lt;SPAN class=""&gt;&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;suspicions&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt; about rewriting the sourcetype twice was impossible, seems to be correct.&lt;BR /&gt;So gotta find another way of solving this.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 12:44:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Possible-to-rewrite-the-sourcetype-twice/m-p/614557#M106340</guid>
      <dc:creator>Fonzie2k</dc:creator>
      <dc:date>2022-09-26T12:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: Possible to rewrite the sourcetype twice?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Possible-to-rewrite-the-sourcetype-twice/m-p/614559#M106341</link>
      <description>&lt;P&gt;Almost that. You can write those e.g. /data/logs/vmware/esx/&amp;lt;hostname&amp;gt;/log-file&lt;/P&gt;&lt;P&gt;and then use wildcard like&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:///data/logs/vmware/esx/*/vmw-syslog]
disabled = false
host_segment = 5
sourcetype = vmw-syslog
index = &amp;lt;vmware index&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Sep 2022 12:56:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Possible-to-rewrite-the-sourcetype-twice/m-p/614559#M106341</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-09-26T12:56:31Z</dc:date>
    </item>
  </channel>
</rss>

