<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can Splunk Auto Change Sourcetype If Input Format Changes in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-Auto-Change-Sourcetype-If-Input-Format-Changes/m-p/195688#M38915</link>
    <description>&lt;P&gt;Martin,&lt;/P&gt;

&lt;P&gt;Maybe I am misunderstanding, but in simple (or well established) cases it detect a pattern and 'sometimes' just get it correct with zero configuration?  In my case, I have now switched the data to be just the key value pairs "k1=v1 k2=v2" (4 keys per line), and now I can do basic searching, so I assume it must be detecting something.  It did not however change the sourcetype.&lt;/P&gt;

&lt;P&gt;I agree, about being explicit in all but none-simple cases, but I would hope ones like this would magically work &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Regards.&lt;/P&gt;

&lt;P&gt;Ron&lt;/P&gt;</description>
    <pubDate>Fri, 21 Mar 2014 17:02:36 GMT</pubDate>
    <dc:creator>rpettymb</dc:creator>
    <dc:date>2014-03-21T17:02:36Z</dc:date>
    <item>
      <title>Can Splunk Auto Change Sourcetype If Input Format Changes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-Auto-Change-Sourcetype-If-Input-Format-Changes/m-p/195686#M38913</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;I have added a new input that looks like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&amp;gt; ...
&amp;gt;     Start calculating postfix queue depth on server1.domain.com at Wed Mar
&amp;gt; 19 22:45:01 UTC 2014
&amp;gt;     instance=1 deferred=1 active=0 incoming=0
&amp;gt;     instance=8 deferred=0 active=0 incoming=0
&amp;gt;     instance=9 deferred=27 active=0 incoming=0
&amp;gt;     Stop calculating postfix queue depth on server1.domain.com at Wed Mar
&amp;gt; 19 22:45:01 UTC 2014
&amp;gt;     Start calculating postfix queue depth on server1.domain.com at Wed Mar
&amp;gt; 19 23:45:01 UTC 2014
&amp;gt;     instance=1 deferred=1 active=0 incoming=0
&amp;gt;     instance=8 deferred=0 active=0 incoming=0
&amp;gt;     instance=9 deferred=27 active=0 incoming=0
&amp;gt;     Stop calculating postfix queue depth on server1.domain.com at Wed Mar
&amp;gt; 19 23:45:01 UTC 2014 ...
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Splunk has applied a sourcetype of *-too_small.  This is causing some grief as I can't simply search for "deferred&amp;gt;25".  I am assuming the lines "Start... and Stop..." are causing Splunk to not auto parse this as I would hope.  If I remove the lines "Start... and Stop..." going forward will Splunk change the sourcetype to something that can be parsed as simple key=value pairs?&lt;/P&gt;

&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 19 Mar 2014 23:20:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-Auto-Change-Sourcetype-If-Input-Format-Changes/m-p/195686#M38913</guid>
      <dc:creator>rpettymb</dc:creator>
      <dc:date>2014-03-19T23:20:51Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk Auto Change Sourcetype If Input Format Changes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-Auto-Change-Sourcetype-If-Input-Format-Changes/m-p/195687#M38914</link>
      <description>&lt;P&gt;How should that data be parsed? Where are the event breaks? Which timestamp should be used?&lt;/P&gt;

&lt;P&gt;It's usually best to define a custom sourcetype for custom data, that will tell Splunk how to index the data - specifically, timestamping and event breaking.&lt;BR /&gt;
After that you can define searchtime field extractions as you need them.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2014 15:06:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-Auto-Change-Sourcetype-If-Input-Format-Changes/m-p/195687#M38914</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-03-21T15:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk Auto Change Sourcetype If Input Format Changes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-Auto-Change-Sourcetype-If-Input-Format-Changes/m-p/195688#M38915</link>
      <description>&lt;P&gt;Martin,&lt;/P&gt;

&lt;P&gt;Maybe I am misunderstanding, but in simple (or well established) cases it detect a pattern and 'sometimes' just get it correct with zero configuration?  In my case, I have now switched the data to be just the key value pairs "k1=v1 k2=v2" (4 keys per line), and now I can do basic searching, so I assume it must be detecting something.  It did not however change the sourcetype.&lt;/P&gt;

&lt;P&gt;I agree, about being explicit in all but none-simple cases, but I would hope ones like this would magically work &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Regards.&lt;/P&gt;

&lt;P&gt;Ron&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2014 17:02:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-Auto-Change-Sourcetype-If-Input-Format-Changes/m-p/195688#M38915</guid>
      <dc:creator>rpettymb</dc:creator>
      <dc:date>2014-03-21T17:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk Auto Change Sourcetype If Input Format Changes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-Auto-Change-Sourcetype-If-Input-Format-Changes/m-p/195689#M38916</link>
      <description>&lt;P&gt;Why are you not specifying a sourcetype in your inputs.conf?&lt;/P&gt;

&lt;P&gt;Just add this to your inputs.conf and restart the forwarder:&lt;/P&gt;

&lt;P&gt;sourcetype=postfixdata&lt;/P&gt;

&lt;P&gt;Or something like that so that Splunk doesn't try to guess at a sourcetype and auto-learn them.&lt;/P&gt;

&lt;P&gt;For this point all new indexed data will be in one sourcetype.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2014 17:14:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-Auto-Change-Sourcetype-If-Input-Format-Changes/m-p/195689#M38916</guid>
      <dc:creator>dmaislin_splunk</dc:creator>
      <dc:date>2014-03-21T17:14:47Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk Auto Change Sourcetype If Input Format Changes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-Auto-Change-Sourcetype-If-Input-Format-Changes/m-p/195690#M38917</link>
      <description>&lt;P&gt;Once that is done we can help you with your linebreaks of the events, field extractions, etc.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2014 17:15:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-Auto-Change-Sourcetype-If-Input-Format-Changes/m-p/195690#M38917</guid>
      <dc:creator>dmaislin_splunk</dc:creator>
      <dc:date>2014-03-21T17:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: Can Splunk Auto Change Sourcetype If Input Format Changes</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-Auto-Change-Sourcetype-If-Input-Format-Changes/m-p/195691#M38918</link>
      <description>&lt;P&gt;The &lt;CODE&gt;*-too_small&lt;/CODE&gt; indicates the sample size was too small for Splunk to guess the sourcetype, even if it may or may not recognize it from a larger sample. That's why I always specify the sourcetype wherever possible - even when it's an automatically recognized one.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Mar 2014 21:00:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-Splunk-Auto-Change-Sourcetype-If-Input-Format-Changes/m-p/195691#M38918</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-03-21T21:00:58Z</dc:date>
    </item>
  </channel>
</rss>

