<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to partition indexed logfiles into multiple sourcetype? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-partition-indexed-logfiles-into-multiple-sourcetype/m-p/617731#M106639</link>
    <description>&lt;P&gt;We need to index logfiles from our monitored devices which are partitioned into two segments.&amp;nbsp; The first segment is CSV.&amp;nbsp; The last segment are events.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;col1,col2,col3,…,colN&lt;/P&gt;
&lt;P&gt;col1,col2,col3,… ,colN&lt;/P&gt;
&lt;P&gt;col1,col2,col3,… ,colN&lt;/P&gt;
&lt;P&gt;.&lt;/P&gt;
&lt;P&gt;.&lt;/P&gt;
&lt;P&gt;.&lt;/P&gt;
&lt;P&gt;event1&lt;/P&gt;
&lt;P&gt;event2&lt;/P&gt;
&lt;P&gt;event3&lt;/P&gt;
&lt;P&gt;…&lt;/P&gt;
&lt;P&gt;eventN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This data from the logfile needs to be sent to one index with a two sourcetypes.&amp;nbsp; Sourcetype_csv for the first segment in the logfile and sourcetype_events for the last segment in the logfile.&amp;nbsp; How do we structure the inputs.conf, props.conf, and transforms.conf for this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We were thinking we could leverage filtering to take advantage that the events are all prefixed and postfixed with “***”.&amp;nbsp; However, there does not seem to be a way to have the one logfile type partitioned into more than one sourcetype.&lt;/P&gt;</description>
    <pubDate>Wed, 19 Oct 2022 17:41:42 GMT</pubDate>
    <dc:creator>edgarrity</dc:creator>
    <dc:date>2022-10-19T17:41:42Z</dc:date>
    <item>
      <title>How to partition indexed logfiles into multiple sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-partition-indexed-logfiles-into-multiple-sourcetype/m-p/617731#M106639</link>
      <description>&lt;P&gt;We need to index logfiles from our monitored devices which are partitioned into two segments.&amp;nbsp; The first segment is CSV.&amp;nbsp; The last segment are events.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;col1,col2,col3,…,colN&lt;/P&gt;
&lt;P&gt;col1,col2,col3,… ,colN&lt;/P&gt;
&lt;P&gt;col1,col2,col3,… ,colN&lt;/P&gt;
&lt;P&gt;.&lt;/P&gt;
&lt;P&gt;.&lt;/P&gt;
&lt;P&gt;.&lt;/P&gt;
&lt;P&gt;event1&lt;/P&gt;
&lt;P&gt;event2&lt;/P&gt;
&lt;P&gt;event3&lt;/P&gt;
&lt;P&gt;…&lt;/P&gt;
&lt;P&gt;eventN&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This data from the logfile needs to be sent to one index with a two sourcetypes.&amp;nbsp; Sourcetype_csv for the first segment in the logfile and sourcetype_events for the last segment in the logfile.&amp;nbsp; How do we structure the inputs.conf, props.conf, and transforms.conf for this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We were thinking we could leverage filtering to take advantage that the events are all prefixed and postfixed with “***”.&amp;nbsp; However, there does not seem to be a way to have the one logfile type partitioned into more than one sourcetype.&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 17:41:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-partition-indexed-logfiles-into-multiple-sourcetype/m-p/617731#M106639</guid>
      <dc:creator>edgarrity</dc:creator>
      <dc:date>2022-10-19T17:41:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to partition indexed logfiles into multiple sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-partition-indexed-logfiles-into-multiple-sourcetype/m-p/617733#M106640</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/216677"&gt;@edgarrity&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you can find a regex to identify logs of the dirst or of the second type, you have two solutions:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;create a rule to assign sourcetype (for more infos see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.1/Data/Configurerule-basedsourcetyperecognition" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/Data/Configurerule-basedsourcetyperecognition&lt;/A&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;override the sourcetype, assign the same sourcetype to both and then overriding one using the regex and following the method you can find at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.1/Data/Advancedsourcetypeoverrides" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.1/Data/Advancedsourcetypeoverrides&lt;/A&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;SPAN&gt;Ciao.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Giuseppe&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Oct 2022 17:28:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-partition-indexed-logfiles-into-multiple-sourcetype/m-p/617733#M106640</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-10-19T17:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to partition indexed logfiles into multiple sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-partition-indexed-logfiles-into-multiple-sourcetype/m-p/617840#M106643</link>
      <description>&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;That worked.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Oct 2022 13:31:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-partition-indexed-logfiles-into-multiple-sourcetype/m-p/617840#M106643</guid>
      <dc:creator>edgarrity</dc:creator>
      <dc:date>2022-10-20T13:31:44Z</dc:date>
    </item>
  </channel>
</rss>

