<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Best pratice for adding knowledge from syslog NG file with forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Best-pratice-for-adding-knowledge-from-syslog-NG-file-with/m-p/58522#M11503</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have a syslogNG with a forwader to splunkindexer, the syslogNG contains 1000+ hosts
Default this will be a single sourcetype (syslog) and shows a nice hostoveride in splunk
Question is now, how to do the enrichment for the field extracts?
Is it possible to do the sourcetype overides on the forwarder? ( in the inputsfile?)
And is it common to do fi 40 or more sourcetypes overrides on this forwarder?&lt;/P&gt;</description>
    <pubDate>Sun, 26 Sep 2010 20:25:26 GMT</pubDate>
    <dc:creator>Starlette</dc:creator>
    <dc:date>2010-09-26T20:25:26Z</dc:date>
    <item>
      <title>Best pratice for adding knowledge from syslog NG file with forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Best-pratice-for-adding-knowledge-from-syslog-NG-file-with/m-p/58522#M11503</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have a syslogNG with a forwader to splunkindexer, the syslogNG contains 1000+ hosts
Default this will be a single sourcetype (syslog) and shows a nice hostoveride in splunk
Question is now, how to do the enrichment for the field extracts?
Is it possible to do the sourcetype overides on the forwarder? ( in the inputsfile?)
And is it common to do fi 40 or more sourcetypes overrides on this forwarder?&lt;/P&gt;</description>
      <pubDate>Sun, 26 Sep 2010 20:25:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Best-pratice-for-adding-knowledge-from-syslog-NG-file-with/m-p/58522#M11503</guid>
      <dc:creator>Starlette</dc:creator>
      <dc:date>2010-09-26T20:25:26Z</dc:date>
    </item>
    <item>
      <title>Re: Best pratice for adding knowledge from syslog NG file with forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Best-pratice-for-adding-knowledge-from-syslog-NG-file-with/m-p/58523#M11504</link>
      <description>&lt;P&gt;I believe you can do what you are wanting by overriding Metadata:Sourcetype in your transforms.conf file based on the regular expression (i.e. REGEX=foo ) pattern match and then mapping it to syslog sourcetype in your props.conf file. &lt;/P&gt;

&lt;P&gt;However, I believe a better practice, depending on your particular reason for wanting to override the sourcetype, would be to leave it as syslog sourcetype and then creating an eventtype for each of your 40+ "situations". That way you have flexibility to add, delete, and/or change the eventtype definitions as you need to, without having to re-index the syslog events. &lt;/P&gt;

&lt;P&gt;(See this page regarding eventtypes and how to setup:)&lt;BR /&gt;
&lt;A href="http://www.splunk.com/base/Documentation/latest/Knowledge/Configureeventtypes" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/Knowledge/Configureeventtypes&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You can also create host tags as well, to group your hosts together for easier logical  searching across common host groups, which when combined with eventtype, makes for a very powerful combination to leverage at search time, rather than at forwarding/indexing time.&lt;/P&gt;

&lt;P&gt;(see this page regarding tagging your hosts:)&lt;BR /&gt;
&lt;A href="http://www.splunk.com/base/Documentation/latest/Knowledge/Tagthehostfield" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/Knowledge/Tagthehostfield&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Oct 2010 04:32:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Best-pratice-for-adding-knowledge-from-syslog-NG-file-with/m-p/58523#M11504</guid>
      <dc:creator>highiqboy</dc:creator>
      <dc:date>2010-10-03T04:32:05Z</dc:date>
    </item>
    <item>
      <title>Re: Best pratice for adding knowledge from syslog NG file with forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Best-pratice-for-adding-knowledge-from-syslog-NG-file-with/m-p/58524#M11505</link>
      <description>&lt;P&gt;Hai&lt;/P&gt;

&lt;P&gt;Thanks for the info,,,bottemline here is the field extractions..so the differentation here is source/sourctype/host,,,and with biljions of events I dont want to do that on a single sourcetype right?&lt;/P&gt;</description>
      <pubDate>Mon, 04 Oct 2010 16:04:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Best-pratice-for-adding-knowledge-from-syslog-NG-file-with/m-p/58524#M11505</guid>
      <dc:creator>Starlette</dc:creator>
      <dc:date>2010-10-04T16:04:18Z</dc:date>
    </item>
  </channel>
</rss>

