<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What sourcetype should I use to index my mongo logs? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-I-use-to-index-my-mongo-logs/m-p/185404#M37121</link>
    <description>&lt;P&gt;I think abrie.strauss is trying to solve the same problem that I am.  I am trying to index mongodb.log files rather than analyze the data stored in Mongo itself.  I don't think Hunk does that.  Ideally, I'd like to say "splunk add monitor -source mongodb.log -sourcetype mongo" and Splunk would properly parse and present Mongo's log data.  If Splunk doesn't have a sourcetype for Mongo logs, surely someone else has made one by now, no?&lt;/P&gt;</description>
    <pubDate>Thu, 28 Aug 2014 01:58:16 GMT</pubDate>
    <dc:creator>pcrook</dc:creator>
    <dc:date>2014-08-28T01:58:16Z</dc:date>
    <item>
      <title>What sourcetype should I use to index my mongo logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-I-use-to-index-my-mongo-logs/m-p/185402#M37119</link>
      <description>&lt;P&gt;We currently have a mongodb cluster who's logs I would like to index to splunk, but there appears to be no sourcetype for mongo logs, what can be done to index the fields in a way that splunk registers the values at time of index? &lt;/P&gt;</description>
      <pubDate>Mon, 18 Aug 2014 13:53:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-I-use-to-index-my-mongo-logs/m-p/185402#M37119</guid>
      <dc:creator>abrie_strauss</dc:creator>
      <dc:date>2014-08-18T13:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: What sourcetype should I use to index my mongo logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-I-use-to-index-my-mongo-logs/m-p/185403#M37120</link>
      <description>&lt;P&gt;Hi abrie.strauss,&lt;/P&gt;

&lt;P&gt;take a look at this app &lt;A href="http://apps.splunk.com/app/1810/"&gt;Hunk App for MongoDB&lt;/A&gt;, maybe this can help.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 19 Aug 2014 08:01:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-I-use-to-index-my-mongo-logs/m-p/185403#M37120</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2014-08-19T08:01:12Z</dc:date>
    </item>
    <item>
      <title>Re: What sourcetype should I use to index my mongo logs?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-I-use-to-index-my-mongo-logs/m-p/185404#M37121</link>
      <description>&lt;P&gt;I think abrie.strauss is trying to solve the same problem that I am.  I am trying to index mongodb.log files rather than analyze the data stored in Mongo itself.  I don't think Hunk does that.  Ideally, I'd like to say "splunk add monitor -source mongodb.log -sourcetype mongo" and Splunk would properly parse and present Mongo's log data.  If Splunk doesn't have a sourcetype for Mongo logs, surely someone else has made one by now, no?&lt;/P&gt;</description>
      <pubDate>Thu, 28 Aug 2014 01:58:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-sourcetype-should-I-use-to-index-my-mongo-logs/m-p/185404#M37121</guid>
      <dc:creator>pcrook</dc:creator>
      <dc:date>2014-08-28T01:58:16Z</dc:date>
    </item>
  </channel>
</rss>

