<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple Inputs on the same File in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Multiple-Inputs-on-the-same-File/m-p/697668#M115721</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/238005"&gt;@TheEggi98&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;if the file to read is always the same in both inputs, Splunk doesn't read twice a file and the solution is the second one I described (overriding).&lt;/P&gt;&lt;P&gt;If instead you have different files in the same path to read in the two inputs, you can specify in the input stanza the different file name to read also using the same path.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Thu, 29 Aug 2024 07:22:52 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2024-08-29T07:22:52Z</dc:date>
    <item>
      <title>Multiple Inputs on the same File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Multiple-Inputs-on-the-same-File/m-p/697663#M115718</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;i have a file monitoring stanza on a universal forwarder where i filter using transforms.conf to only get logentries i need, because the server writes logentries of multiple business processes into the same logfile.&lt;BR /&gt;&lt;BR /&gt;Now i need entries of another process with different ACL in a different index from that logfile but in our QS cluster while the first datainput still ingests into our PROD cluster&lt;BR /&gt;&lt;BR /&gt;So i have my inputs.conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor://&amp;lt;path_to_logfile&amp;gt;]
disabled = 0
index = &amp;lt;dataspecific index 1&amp;gt;
sourcetype = &amp;lt;dataspecific sourcetype 1&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;a props.conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[&amp;lt;dataspecific sourcetype 1&amp;gt;]
SHOULD_LINEMERGE        = true
BREAK_ONLY_BEFORE_DATE  = true
TRUNCATE                = 1500
TIME_PREFIX             = ^
MAX_TIMESTAMP_LOOKAHEAD = 20
TIME_FORMAT             = [%y/%m/%d %H:%M:%S]
TRANSFORMS-set 			= setnull, setparsing&lt;/LI-CODE&gt;&lt;P&gt;and a transforms.conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[setnull]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue

[setparsing]
REGEX = (&amp;lt;specific regex&amp;gt;)
DEST_KEY = queue
FORMAT = indexQueue&lt;/LI-CODE&gt;&lt;P&gt;&lt;BR /&gt;As standalone Stanza i would need the new input like this, with its own setparsing transforms&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor://&amp;lt;path_to_logfile&amp;gt;]
disabled = 0
index = &amp;lt;dataspecific index 2&amp;gt;
sourcetype = &amp;lt;dataspecific sourcetype 2&amp;gt;
_TCP_ROUTING = qs_cluster&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;to be honest i could just create a second stanza thats a little different and still reads the same file, but i dont want two tailreader on the same file.&lt;BR /&gt;&lt;BR /&gt;What possibilities do i have?&lt;BR /&gt;Thanks in advance&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 06:59:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Multiple-Inputs-on-the-same-File/m-p/697663#M115718</guid>
      <dc:creator>TheEggi98</dc:creator>
      <dc:date>2024-08-29T06:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Inputs on the same File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Multiple-Inputs-on-the-same-File/m-p/697666#M115719</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/238005"&gt;@TheEggi98&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you cannot read the same files in two input stanzas, ony one (by precedence rules) will be used.&lt;/P&gt;&lt;P&gt;If in the same path, you have to read different files for each input, you can specify in the stanzas the correct file to read.&lt;/P&gt;&lt;P&gt;If instead data are in the same file, the only solution is to read it with one input stanza and then override index and eventually sourcetype values on the Indexers or (if present) on Heavy Forwarders, following the instructions at&amp;nbsp;&lt;/P&gt;&lt;P&gt;for sourcetype&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.2.2203/Data/Advancedsourcetypeoverrides?_gl=1*4u2o7n*_gcl_au*NTk4MTY5Ny4xNzI0ODM2ODI0*FPAU*NTk4MTY5Ny4xNzI0ODM2ODI0*_ga*MTY2Mzg1NDI2Mi4xNzI0ODM2ODI0*_ga_5EPM2P39FV*MTcyNDkxNDM3OC41LjEuMTcyNDkxNTE2NS4wLjAuMTM4NTMxMDQ2NA..*_fplc*SVZreWQzalBQTTVYVjFvczZ3Sm45a3lBd1REUGtiV3c4bktjeDdzejliWm9NbEYlMkJ2Z2VGb2E4JTJCYzdsNld4QSUyQmJ0NnAwVTNKaU93OWJGbk1uSmVBa0R3M3l4ZWcyNElnZFZISldBS0VlOSUyRmxycm00UUp5NXdDd2xXb3clMkJXQSUzRCUzRA." target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.2.2203/Data/Advancedsourcetypeoverrides?_gl=1*4u2o7n*_gcl_au*NTk4MTY5Ny4xNzI0ODM2ODI0*FPAU*NTk4MTY5Ny4xNzI0ODM2ODI0*_ga*MTY2Mzg1NDI2Mi4xNzI0ODM2ODI0*_ga_5EPM2P39FV*MTcyNDkxNDM3OC41LjEuMTcyNDkxNTE2NS4wLjAuMTM4NTMxMDQ2NA..*_fplc*SVZreWQzalBQTTVYVjFvczZ3Sm45a3lBd1REUGtiV3c4bktjeDdzejliWm9NbEYlMkJ2Z2VGb2E4JTJCYzdsNld4QSUyQmJ0NnAwVTNKaU93OWJGbk1uSmVBa0R3M3l4ZWcyNElnZFZISldBS0VlOSUyRmxycm00UUp5NXdDd2xXb3clMkJXQSUzRCUzRA.&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;and for index&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Route-data-to-index-based-on-host/td-p/10887?_gl=1*1079w7n*_gcl_au*NTk4MTY5Ny4xNzI0ODM2ODI0*FPAU*NTk4MTY5Ny4xNzI0ODM2ODI0*_ga*MTY2Mzg1NDI2Mi4xNzI0ODM2ODI0*_ga_5EPM2P39FV*MTcyNDkxNDM3OC41LjEuMTcyNDkxNTIxNS4wLjAuMTM4NTMxMDQ2NA..*_fplc*M29uUHdZbnRsT3VuRlgxaktXenFld01sdDJ1dXVqcFExYTRDSFF5OTZRd2pTRmFzRGE4OU11YUZaS0dtdG5iSWNuckRxTGRFT2l4cDVrZDlQTnNLUTFEOVVIemRxQyUyQjhyTmpvJTJGeUZ5bUs1Vng2eWtkMUxWcEpSdDFQWEtZQSUzRCUzRA." target="_blank"&gt;https://community.splunk.com/t5/Getting-Data-In/Route-data-to-index-based-on-host/td-p/10887?_gl=1*1079w7n*_gcl_au*NTk4MTY5Ny4xNzI0ODM2ODI0*FPAU*NTk4MTY5Ny4xNzI0ODM2ODI0*_ga*MTY2Mzg1NDI2Mi4xNzI0ODM2ODI0*_ga_5EPM2P39FV*MTcyNDkxNDM3OC41LjEuMTcyNDkxNTIxNS4wLjAuMTM4NTMxMDQ2NA..*_fplc*M29uUHdZbnRsT3VuRlgxaktXenFld01sdDJ1dXVqcFExYTRDSFF5OTZRd2pTRmFzRGE4OU11YUZaS0dtdG5iSWNuckRxTGRFT2l4cDVrZDlQTnNLUTFEOVVIemRxQyUyQjhyTmpvJTJGeUZ5bUs1Vng2eWtkMUxWcEpSdDFQWEtZQSUzRCUzRA.&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 07:09:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Multiple-Inputs-on-the-same-File/m-p/697666#M115719</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-08-29T07:09:06Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Inputs on the same File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Multiple-Inputs-on-the-same-File/m-p/697667#M115720</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;BR /&gt;thanks for the fast response.&lt;BR /&gt;&lt;BR /&gt;if im not wrong i theoretically could bypass the precedence by doing this (at least btool dont complain) but i will not do that&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor://&amp;lt;path to logfile&amp;gt;.log]
...

[monitor://&amp;lt;path to same logfile&amp;gt;.lo*]
...&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;BR /&gt;When overriding sourcetype and index on the indexer, am i able to route data of the second sourcetype to our qs cluster to build dashboards?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 07:17:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Multiple-Inputs-on-the-same-File/m-p/697667#M115720</guid>
      <dc:creator>TheEggi98</dc:creator>
      <dc:date>2024-08-29T07:17:03Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Inputs on the same File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Multiple-Inputs-on-the-same-File/m-p/697668#M115721</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/238005"&gt;@TheEggi98&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;if the file to read is always the same in both inputs, Splunk doesn't read twice a file and the solution is the second one I described (overriding).&lt;/P&gt;&lt;P&gt;If instead you have different files in the same path to read in the two inputs, you can specify in the input stanza the different file name to read also using the same path.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 07:22:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Multiple-Inputs-on-the-same-File/m-p/697668#M115721</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-08-29T07:22:52Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Inputs on the same File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Multiple-Inputs-on-the-same-File/m-p/697670#M115723</link>
      <description>&lt;P&gt;Alright Thank you&lt;BR /&gt;&lt;BR /&gt;i will use sourcetype and index overriding and then make the data of the newly added available for our qs cluster to build dashboards&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 07:36:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Multiple-Inputs-on-the-same-File/m-p/697670#M115723</guid>
      <dc:creator>TheEggi98</dc:creator>
      <dc:date>2024-08-29T07:36:47Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Inputs on the same File</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Multiple-Inputs-on-the-same-File/m-p/697671#M115724</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/238005"&gt;@TheEggi98&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Aug 2024 07:40:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Multiple-Inputs-on-the-same-File/m-p/697671#M115724</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2024-08-29T07:40:17Z</dc:date>
    </item>
  </channel>
</rss>

