<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do i make stored logs be parsed according to a diffrent sourcetype? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-make-stored-logs-be-parsed-according-to-a-diffrent/m-p/280107#M53614</link>
    <description>&lt;P&gt;You will need to change the sourcetype on the host machine(s) where the forwarder is installed on. You will edit the &lt;CODE&gt;inputs.conf&lt;/CODE&gt; and change the sourcetype there &lt;/P&gt;

&lt;P&gt;What's the name of the app and which machine did you install the app on? I'm assuming you will need it installed on the indexer since that does the parsing.. &lt;/P&gt;</description>
    <pubDate>Mon, 25 Jul 2016 17:05:47 GMT</pubDate>
    <dc:creator>skoelpin</dc:creator>
    <dc:date>2016-07-25T17:05:47Z</dc:date>
    <item>
      <title>How do i make stored logs be parsed according to a diffrent sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-make-stored-logs-be-parsed-according-to-a-diffrent/m-p/280105#M53612</link>
      <description>&lt;P&gt;I have a logs stored in splunk and they are of sourcetype=test, but I recently found this app that parses these type of logs but it needs a different sourcetype (sourcetype=good_type) to parse them. I tried sourcetype renaming but it only changed the name of the sourcetype but the logs did not get parsed by the app.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2016 15:47:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-make-stored-logs-be-parsed-according-to-a-diffrent/m-p/280105#M53612</guid>
      <dc:creator>mkudejim</dc:creator>
      <dc:date>2016-07-25T15:47:40Z</dc:date>
    </item>
    <item>
      <title>Re: How do i make stored logs be parsed according to a diffrent sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-make-stored-logs-be-parsed-according-to-a-diffrent/m-p/280106#M53613</link>
      <description>&lt;P&gt;You would need to update the inputs.conf using which the data is collected to change the sourcetype from test to good_type (recommended). In order for new sourcetype parsing to take place, it has to apply before it's indexed.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2016 17:05:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-make-stored-logs-be-parsed-according-to-a-diffrent/m-p/280106#M53613</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-07-25T17:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: How do i make stored logs be parsed according to a diffrent sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-make-stored-logs-be-parsed-according-to-a-diffrent/m-p/280107#M53614</link>
      <description>&lt;P&gt;You will need to change the sourcetype on the host machine(s) where the forwarder is installed on. You will edit the &lt;CODE&gt;inputs.conf&lt;/CODE&gt; and change the sourcetype there &lt;/P&gt;

&lt;P&gt;What's the name of the app and which machine did you install the app on? I'm assuming you will need it installed on the indexer since that does the parsing.. &lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2016 17:05:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-make-stored-logs-be-parsed-according-to-a-diffrent/m-p/280107#M53614</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2016-07-25T17:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: How do i make stored logs be parsed according to a diffrent sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-make-stored-logs-be-parsed-according-to-a-diffrent/m-p/280108#M53615</link>
      <description>&lt;P&gt;After setting the new sourcetype, I assume you want to re-index the data, right? It means running the soft delete using &lt;CODE&gt;| delete&lt;/CODE&gt; for this data and clearing the caching in the &lt;CODE&gt;fishbucket&lt;/CODE&gt; - definitely at the forwarder level but potentially also at the index level.&lt;/P&gt;

&lt;P&gt;Then when re-indexing and having the modified &lt;CODE&gt;inputs.conf&lt;/CODE&gt;, you should be fine.&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2016 17:20:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-make-stored-logs-be-parsed-according-to-a-diffrent/m-p/280108#M53615</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2016-07-25T17:20:45Z</dc:date>
    </item>
    <item>
      <title>Re: How do i make stored logs be parsed according to a diffrent sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-make-stored-logs-be-parsed-according-to-a-diffrent/m-p/280109#M53616</link>
      <description>&lt;P&gt;It's TA for Symantec Endpoint Protection (syslog), I installed the app on the search head and the forwarder, I would need to install it on the indexer right?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2016 17:34:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-make-stored-logs-be-parsed-according-to-a-diffrent/m-p/280109#M53616</guid>
      <dc:creator>mkudejim</dc:creator>
      <dc:date>2016-07-25T17:34:15Z</dc:date>
    </item>
    <item>
      <title>Re: How do i make stored logs be parsed according to a diffrent sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-make-stored-logs-be-parsed-according-to-a-diffrent/m-p/280110#M53617</link>
      <description>&lt;P&gt;Are you using Universal Forwarders or a Heavy Forwarder? &lt;/P&gt;

&lt;P&gt;Universal forwarders are unable to parse data, they can only forward data to the indexer which will then parse it. So for this app to work, it will need to be on the indexer and you will need to change your sourcetype name on the forwarder in the &lt;CODE&gt;inputs.conf&lt;/CODE&gt; file.&lt;/P&gt;

&lt;P&gt;So go onto one of your forwarders to test this and go to &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;Splunk/etc/system/local/inputs.conf&lt;/CODE&gt; and change your sourcetype &lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2016 17:49:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-make-stored-logs-be-parsed-according-to-a-diffrent/m-p/280110#M53617</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2016-07-25T17:49:23Z</dc:date>
    </item>
    <item>
      <title>Re: How do i make stored logs be parsed according to a diffrent sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-make-stored-logs-be-parsed-according-to-a-diffrent/m-p/280111#M53618</link>
      <description>&lt;P&gt;would I add a stanza like this one to inputs.conf to change the sourcetype?&lt;/P&gt;

&lt;P&gt;[test]&lt;BR /&gt;
rename=good_type&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2016 18:22:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-make-stored-logs-be-parsed-according-to-a-diffrent/m-p/280111#M53618</guid>
      <dc:creator>mkudejim</dc:creator>
      <dc:date>2016-07-25T18:22:43Z</dc:date>
    </item>
    <item>
      <title>Re: How do i make stored logs be parsed according to a diffrent sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-make-stored-logs-be-parsed-according-to-a-diffrent/m-p/280112#M53619</link>
      <description>&lt;P&gt;Your stanza in &lt;CODE&gt;inputs.conf&lt;/CODE&gt; should look like this&lt;/P&gt;

&lt;P&gt;Make sure to put in the hostname of the machine, the path you want to monitor, and the index you want this to go into.. Also make sure you restart the forwarder service after making these changes&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[default]
host = SERVERNAME

[monitor://PATH_NAME]
disabled = false
sourcetype = good_type
index = YOUR INDEX
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 25 Jul 2016 18:36:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-make-stored-logs-be-parsed-according-to-a-diffrent/m-p/280112#M53619</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2016-07-25T18:36:45Z</dc:date>
    </item>
    <item>
      <title>Re: How do i make stored logs be parsed according to a diffrent sourcetype?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-i-make-stored-logs-be-parsed-according-to-a-diffrent/m-p/280113#M53620</link>
      <description>&lt;P&gt;Were you able to get this going? If this helped then can you accept/like the answer&lt;/P&gt;</description>
      <pubDate>Tue, 26 Jul 2016 13:50:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-i-make-stored-logs-be-parsed-according-to-a-diffrent/m-p/280113#M53620</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2016-07-26T13:50:05Z</dc:date>
    </item>
  </channel>
</rss>

