<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change sourcetype in props.conf in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Change-sourcetype-in-props-conf/m-p/56792#M11058</link>
    <description>&lt;P&gt;Yes that does help thanks, but then I have to break out my access logs into a separate input.  Right now I'm watching all of /var/log and the access logs are within there.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Sep 2010 21:45:35 GMT</pubDate>
    <dc:creator>dswanson99</dc:creator>
    <dc:date>2010-09-23T21:45:35Z</dc:date>
    <item>
      <title>Change sourcetype in props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-sourcetype-in-props-conf/m-p/56790#M11056</link>
      <description>&lt;P&gt;I have a lwf sending apache logs (/var/log/httpd/access.log) to an indexer and they're being sourcetyped as 'unknown'.&lt;/P&gt;

&lt;P&gt;On the forwarder in props.conf I have:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[source::/var/log/httpd/access.log(.\d+)?]
sourcetype = apache_access
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Assuming this is the correct place, what am I doing wrong.  I think I might be able to also do a transform but thought I'd stick with this for now.&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2010 20:50:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-sourcetype-in-props-conf/m-p/56790#M11056</guid>
      <dc:creator>dswanson99</dc:creator>
      <dc:date>2010-09-23T20:50:43Z</dc:date>
    </item>
    <item>
      <title>Re: Change sourcetype in props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-sourcetype-in-props-conf/m-p/56791#M11057</link>
      <description>&lt;P&gt;I set my sourcetype in inputs.conf. Here's what my inputs.conf looks like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor:///etc/httpd/logs/ssl_access_log]
index=access
sourcetype=apache-access
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Hope that helps!&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2010 21:16:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-sourcetype-in-props-conf/m-p/56791#M11057</guid>
      <dc:creator>Branden</dc:creator>
      <dc:date>2010-09-23T21:16:04Z</dc:date>
    </item>
    <item>
      <title>Re: Change sourcetype in props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-sourcetype-in-props-conf/m-p/56792#M11058</link>
      <description>&lt;P&gt;Yes that does help thanks, but then I have to break out my access logs into a separate input.  Right now I'm watching all of /var/log and the access logs are within there.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2010 21:45:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-sourcetype-in-props-conf/m-p/56792#M11058</guid>
      <dc:creator>dswanson99</dc:creator>
      <dc:date>2010-09-23T21:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: Change sourcetype in props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-sourcetype-in-props-conf/m-p/56793#M11059</link>
      <description>&lt;P&gt;Your log files end up under &lt;CODE&gt;/etc&lt;/CODE&gt;?  That seems odd.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Sep 2010 21:55:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-sourcetype-in-props-conf/m-p/56793#M11059</guid>
      <dc:creator>Lowell</dc:creator>
      <dc:date>2010-09-23T21:55:39Z</dc:date>
    </item>
    <item>
      <title>Re: Change sourcetype in props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-sourcetype-in-props-conf/m-p/56794#M11060</link>
      <description>&lt;P&gt;Looks right to me, and you would much rather do this than a transform. are you sure the file isn't &lt;CODE&gt;access_log&lt;/CODE&gt; vs &lt;CODE&gt;access.log&lt;/CODE&gt;?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2010 12:40:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-sourcetype-in-props-conf/m-p/56794#M11060</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2010-09-24T12:40:15Z</dc:date>
    </item>
    <item>
      <title>Re: Change sourcetype in props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-sourcetype-in-props-conf/m-p/56795#M11061</link>
      <description>&lt;P&gt;I wish that was the problem, but no they're access.log.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Sep 2010 19:30:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-sourcetype-in-props-conf/m-p/56795#M11061</guid>
      <dc:creator>dswanson99</dc:creator>
      <dc:date>2010-09-24T19:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: Change sourcetype in props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-sourcetype-in-props-conf/m-p/56796#M11062</link>
      <description>&lt;P&gt;If you have a file/directory that is matched in multiple regex patterns it is important to help Splunk know which one you want to win. Defaul priority is 100, and it is possible that you have something like /var/log defined with another sourcetype.&lt;/P&gt;

&lt;P&gt;I would try changing the priority in your props.conf to be &amp;gt; 100, and maybe just use a regex at the end. You can specify what files to eat in your inputs.conf&lt;/P&gt;

&lt;P&gt;props.conf
[source::/var/log/httpd/access.log*]
sourcetype = apache_access
priority = 101&lt;/P&gt;

&lt;P&gt;I hope that helps.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Nov 2010 23:22:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-sourcetype-in-props-conf/m-p/56796#M11062</guid>
      <dc:creator>brianirwin</dc:creator>
      <dc:date>2010-11-24T23:22:03Z</dc:date>
    </item>
    <item>
      <title>Re: Change sourcetype in props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Change-sourcetype-in-props-conf/m-p/56797#M11063</link>
      <description>&lt;P&gt;The forwarder's &lt;CODE&gt;props.conf&lt;/CODE&gt; must have a &lt;CODE&gt;force_local_processing = true&lt;/CODE&gt; clause in the appropriate &lt;CODE&gt;sourcetype&lt;/CODE&gt; or &lt;CODE&gt;source::&lt;/CODE&gt; stanza. Be aware that this will make the forwarder's &lt;CODE&gt;SEDCMD&lt;/CODE&gt; and &lt;CODE&gt;TRANSFORMS&lt;/CODE&gt; clauses apply and prevent those on the indexer from applying. Forwarders cannot do any search-time extractions, transformations, lookups or aliasing.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Feb 2018 17:02:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Change-sourcetype-in-props-conf/m-p/56797#M11063</guid>
      <dc:creator>DUThibault</dc:creator>
      <dc:date>2018-02-05T17:02:26Z</dc:date>
    </item>
  </channel>
</rss>

