<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sourcetype won't split on monitored file after changing transforms.conf and props.conf. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-won-t-split-on-monitored-file-after-changing/m-p/296963#M56292</link>
    <description>&lt;P&gt;Strange. Can you try to log in to Splunk web of your Test box and go to Settings-&amp;gt; Sourcetype and check if you see the updated sourcetype with new settings? &lt;/P&gt;</description>
    <pubDate>Mon, 13 Feb 2017 22:33:19 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2017-02-13T22:33:19Z</dc:date>
    <item>
      <title>Sourcetype won't split on monitored file after changing transforms.conf and props.conf.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-won-t-split-on-monitored-file-after-changing/m-p/296957#M56286</link>
      <description>&lt;P&gt;I am testing splitting sourcetypes for a one time indexed file on my test box. All time formats are parsed correctly when the log ingests. The file splits just fine into exactly as many events as expected. &lt;/P&gt;

&lt;P&gt;But there are 3 sourcetypes I need to split it into: Send, receive and scan as the message section of the logs vary heavily. The regex has been tested and works fine. No errors from btool.&lt;/P&gt;

&lt;P&gt;inputs.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; [monitor://C:\\Users\\&amp;lt;user&amp;gt;\\Desktop\\security\\Splunk\\DEVELOPMENT\\Test_Ingest\\test_raw_spam.txt]
 disabled = false
 sourcetype = test_barracuda
 index = test
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;props.conf - to note, I tried the TRANSFORMS- line in the test_barracuda stanza, but still no results.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[test_barracuda]
CHARSET=AUTO
NO_BINARY_CHECK=true
SHOULD_LINEMERGE=true
category=Custom
disabled=false
pulldown_type=true

[source:\\C:\\Users\\&amp;lt;user&amp;gt;\\Desktop\\security\\Splunk\\DEVELOPMENT\\Test_Ingest\\test_raw_spam.txt]
TRANSFORMS-changesourcetype = send_set_sourcetype, recv_set_sourcetype, scan_set_sourcetype
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Transfoms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[send_set_sourcetype]
DEST_KEY = MetaData:Sourcetype
REGEX = (\sSEND\s)
FORMAT = sourcetype::test_send

[recv_set_sourcetype]
DEST_KEY = MetaData:Sourcetype
REGEX = (\sRECV\s)
FORMAT = sourcetype::test_recv

[scan_set_sourcetype]
DEST_KEY = MetaData:Sourcetype
REGEX = (\sSCAN\s)
FORMAT = sourcetype::test_send
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;When I do a search after resetting, I am not seeing any results in the new sourcetypes, only in test_barricuda. Any thoughts? &lt;/P&gt;

&lt;P&gt;I forced re-indexing of all file monitors because of the fact that this was a one time monitor, still no results in new sourcetypes. &lt;/P&gt;

&lt;P&gt;command used: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk clean eventdata _thefishbucket
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 13 Feb 2017 20:58:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-won-t-split-on-monitored-file-after-changing/m-p/296957#M56286</guid>
      <dc:creator>EdgarAllenProse</dc:creator>
      <dc:date>2017-02-13T20:58:16Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype won't split on monitored file after changing transforms.conf and props.conf.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-won-t-split-on-monitored-file-after-changing/m-p/296958#M56287</link>
      <description>&lt;P&gt;Can we have a sample event?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 21:38:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-won-t-split-on-monitored-file-after-changing/m-p/296958#M56287</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-02-13T21:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype won't split on monitored file after changing transforms.conf and props.conf.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-won-t-split-on-monitored-file-after-changing/m-p/296959#M56288</link>
      <description>&lt;P&gt;Here is a sample containing each type of event: anonymized, but not in a way that would conflict with regex or the confs.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Feb 13 12:14:57 192.168.x.x outbound/smtp: 127.0.0.1 1487013294-09b08c0e0d22d7b0001-vy5CMk 0 0 SEND - 1 0112918C8063 250 2.6.0 &amp;lt;2050829162.21743.1487013293752.JavaMail@dc1prjasszap434.whc&amp;gt; [InternalId=91736206477550, Hostname=host.prod.outlook.com] 11518 bytes in 0.192, 58.365 KB/sec Queued mail for delivery #to#name-com.mail.protection.outlook.com[8.8.8.8]:25

Feb 13 12:14:56 192.168.x.x  scan: mail2-3.place.com[8.8.8.8] 1487013294-09b08c0e0d22d7b0001-vy5CMk 1487013294 1487013296 SCAN - prvs=7217d0fa1f=services_noreply@place.com name@otherplace.com - 7 88 corporate SZ:3263 SUBJ:Message: Attempt to retrieve your User ID

Feb 13 12:14:15 192.168.x.x  inbound/pass1: name.place1.com[8.8.8.8] 1487013254-09b08c0e0e22d7a0001-VY5SBA 1487013254 1487013255 RECV information=place2.com@thing.com name@thingy1.com 2 3 blacklist.org[8.8.8.8]
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 13 Feb 2017 21:58:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-won-t-split-on-monitored-file-after-changing/m-p/296959#M56288</guid>
      <dc:creator>EdgarAllenProse</dc:creator>
      <dc:date>2017-02-13T21:58:24Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype won't split on monitored file after changing transforms.conf and props.conf.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-won-t-split-on-monitored-file-after-changing/m-p/296960#M56289</link>
      <description>&lt;P&gt;Give this a try&lt;/P&gt;

&lt;P&gt;input.conf (same)&lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[test_barracuda]
CHARSET=AUTO
NO_BINARY_CHECK=true
SHOULD_LINEMERGE=true
category=Custom
disabled=false
pulldown_type=true
TRANSFORMS-overridest = set_sourcetype
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[set_sourcetype]
DEST_KEY = MetaData:Sourcetype
REGEX = \d+\s+(SEND|SCAN|RECV)\s
FORMAT = sourcetype::test_$1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Assuming you've a standalone Splunk instance, so restart Splunk after you make the change.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 22:06:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-won-t-split-on-monitored-file-after-changing/m-p/296960#M56289</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-02-13T22:06:11Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype won't split on monitored file after changing transforms.conf and props.conf.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-won-t-split-on-monitored-file-after-changing/m-p/296961#M56290</link>
      <description>&lt;P&gt;I plugged those in and cleaned the fishbucket, then restarted still didn't work.&lt;/P&gt;

&lt;P&gt;query &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;index=* NOT (sourcetype=Win* OR sourcetype=Perf*) | stats count by sourcetype
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;results in&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;sourcetype      count   
Test               3825
shiftlog              42
test_barracuda  22950 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 13 Feb 2017 22:15:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-won-t-split-on-monitored-file-after-changing/m-p/296961#M56290</guid>
      <dc:creator>EdgarAllenProse</dc:creator>
      <dc:date>2017-02-13T22:15:58Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype won't split on monitored file after changing transforms.conf and props.conf.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-won-t-split-on-monitored-file-after-changing/m-p/296962#M56291</link>
      <description>&lt;P&gt;Is it okay that I did these in splunk_home/etc/app/search/local/?&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 22:31:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-won-t-split-on-monitored-file-after-changing/m-p/296962#M56291</guid>
      <dc:creator>EdgarAllenProse</dc:creator>
      <dc:date>2017-02-13T22:31:42Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype won't split on monitored file after changing transforms.conf and props.conf.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-won-t-split-on-monitored-file-after-changing/m-p/296963#M56292</link>
      <description>&lt;P&gt;Strange. Can you try to log in to Splunk web of your Test box and go to Settings-&amp;gt; Sourcetype and check if you see the updated sourcetype with new settings? &lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 22:33:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-won-t-split-on-monitored-file-after-changing/m-p/296963#M56292</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2017-02-13T22:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype won't split on monitored file after changing transforms.conf and props.conf.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-won-t-split-on-monitored-file-after-changing/m-p/296964#M56293</link>
      <description>&lt;P&gt;It did not update in the settings&lt;/P&gt;</description>
      <pubDate>Mon, 13 Feb 2017 22:44:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-won-t-split-on-monitored-file-after-changing/m-p/296964#M56293</guid>
      <dc:creator>EdgarAllenProse</dc:creator>
      <dc:date>2017-02-13T22:44:58Z</dc:date>
    </item>
  </channel>
</rss>

