<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Where is the default sourcetype for udp:514 set? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-default-sourcetype-for-udp-514-set/m-p/153506#M31199</link>
    <description>&lt;P&gt;There is no default.  You have to set up an UDP listener inside some &lt;CODE&gt;inputs.conf&lt;/CODE&gt;.  Try this search on your forwarder:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;cd $SPLUNK_HOME; find . -name inputs.conf -exec grep -il 514 {} \;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Tue, 04 Aug 2015 13:40:42 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2015-08-04T13:40:42Z</dc:date>
    <item>
      <title>Where is the default sourcetype for udp:514 set?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-default-sourcetype-for-udp-514-set/m-p/153505#M31198</link>
      <description>&lt;P&gt;The sourcetype for udp514 is set to syslog. Where is this defined? Is it hard coded in Splunkd or is it defined in a file in &lt;CODE&gt;/opt/splunk&lt;/CODE&gt;? If the latter, where is it defined?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;Sean Coleman&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2015 06:00:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-default-sourcetype-for-udp-514-set/m-p/153505#M31198</guid>
      <dc:creator>coleman07</dc:creator>
      <dc:date>2015-08-04T06:00:05Z</dc:date>
    </item>
    <item>
      <title>Re: Where is the default sourcetype for udp:514 set?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-default-sourcetype-for-udp-514-set/m-p/153506#M31199</link>
      <description>&lt;P&gt;There is no default.  You have to set up an UDP listener inside some &lt;CODE&gt;inputs.conf&lt;/CODE&gt;.  Try this search on your forwarder:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;cd $SPLUNK_HOME; find . -name inputs.conf -exec grep -il 514 {} \;
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 04 Aug 2015 13:40:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-default-sourcetype-for-udp-514-set/m-p/153506#M31199</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-08-04T13:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Where is the default sourcetype for udp:514 set?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-default-sourcetype-for-udp-514-set/m-p/153507#M31200</link>
      <description>&lt;P&gt;or use btool and look at the location of your stanza udp:514&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;./splunk cmd btool inputs list udp --debug
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 04 Aug 2015 14:43:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-default-sourcetype-for-udp-514-set/m-p/153507#M31200</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2015-08-04T14:43:06Z</dc:date>
    </item>
  </channel>
</rss>

