<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Where is the logtype source type defined? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-logtype-source-type-defined/m-p/303478#M57299</link>
    <description>&lt;P&gt;I've added a (universal) forwarder's local &lt;CODE&gt;/var/log&lt;/CODE&gt; as a data input, specifying &lt;CODE&gt;sourcetype = automatic&lt;/CODE&gt;. For &lt;CODE&gt;audit.log&lt;/CODE&gt;, the indexed data are all marked with &lt;CODE&gt;sourcetype=logtype&lt;/CODE&gt;, but &lt;CODE&gt;logtype&lt;/CODE&gt; is not found in &lt;CODE&gt;Settings: (Data) Source types&lt;/CODE&gt;. Where is &lt;CODE&gt;logtype&lt;/CODE&gt; defined?&lt;/P&gt;</description>
    <pubDate>Fri, 24 Nov 2017 15:20:53 GMT</pubDate>
    <dc:creator>DUThibault</dc:creator>
    <dc:date>2017-11-24T15:20:53Z</dc:date>
    <item>
      <title>Where is the logtype source type defined?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-logtype-source-type-defined/m-p/303478#M57299</link>
      <description>&lt;P&gt;I've added a (universal) forwarder's local &lt;CODE&gt;/var/log&lt;/CODE&gt; as a data input, specifying &lt;CODE&gt;sourcetype = automatic&lt;/CODE&gt;. For &lt;CODE&gt;audit.log&lt;/CODE&gt;, the indexed data are all marked with &lt;CODE&gt;sourcetype=logtype&lt;/CODE&gt;, but &lt;CODE&gt;logtype&lt;/CODE&gt; is not found in &lt;CODE&gt;Settings: (Data) Source types&lt;/CODE&gt;. Where is &lt;CODE&gt;logtype&lt;/CODE&gt; defined?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 15:20:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-logtype-source-type-defined/m-p/303478#M57299</guid>
      <dc:creator>DUThibault</dc:creator>
      <dc:date>2017-11-24T15:20:53Z</dc:date>
    </item>
    <item>
      <title>Re: Where is the logtype source type defined?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-logtype-source-type-defined/m-p/303479#M57300</link>
      <description>&lt;P&gt;Hi  DUThibault,&lt;BR /&gt;
see in Indexer.&lt;BR /&gt;
Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 15:23:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-logtype-source-type-defined/m-p/303479#M57300</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-11-24T15:23:10Z</dc:date>
    </item>
    <item>
      <title>Re: Where is the logtype source type defined?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-logtype-source-type-defined/m-p/303480#M57301</link>
      <description>&lt;P&gt;Where, exactly? In Splunk Web, no Indexer to be found. Searching docs.splunk.com for "indexer source type" yields 90 hits but no obvious answer.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 15:34:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-logtype-source-type-defined/m-p/303480#M57301</guid>
      <dc:creator>DUThibault</dc:creator>
      <dc:date>2017-11-24T15:34:26Z</dc:date>
    </item>
    <item>
      <title>Re: Where is the logtype source type defined?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-logtype-source-type-defined/m-p/303481#M57302</link>
      <description>&lt;P&gt;Hi DUThibault,&lt;BR /&gt;
what is your architecture? do you have an all-in-one server or do you have search Heads and Indexers?&lt;/P&gt;

&lt;P&gt;Anyway, you can find in Splunk server (not Forwarders) sourcetypes in [Settings -- Source types].&lt;BR /&gt;
I searched logtype in my installation and I didn't find it!&lt;/P&gt;

&lt;P&gt;Pretrained sourcetypes are described in &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.0.0/Data/Listofpretrainedsourcetypes"&gt;https://docs.splunk.com/Documentation/Splunk/7.0.0/Data/Listofpretrainedsourcetypes&lt;/A&gt; and &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.0/Data/Whysourcetypesmatter"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.0/Data/Whysourcetypesmatter&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Bye.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 15:48:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-logtype-source-type-defined/m-p/303481#M57302</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2017-11-24T15:48:00Z</dc:date>
    </item>
    <item>
      <title>Re: Where is the logtype source type defined?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-logtype-source-type-defined/m-p/303482#M57303</link>
      <description>&lt;P&gt;My architecture is minimalistic, with a single instance indexer and search head, fed by one or more universal forwarders.&lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;logtype&lt;/CODE&gt; is not in the list of pre-trained source types, all of which are listed in &lt;CODE&gt;Settings: (Data) Source types&lt;/CODE&gt; &lt;EM&gt;except in three cases&lt;/EM&gt;: &lt;CODE&gt;sugarcrm_log4php&lt;/CODE&gt; is absent, while &lt;CODE&gt;websphere_trlog_syserr&lt;/CODE&gt; and &lt;CODE&gt;websphere_trlog_sysout&lt;/CODE&gt; seem to have been merged into a single &lt;CODE&gt;websphere_trlog&lt;/CODE&gt; source type. Could the 7.0.0 documentation pages be incorrect or out of date?&lt;/P&gt;

&lt;P&gt;Note that &lt;CODE&gt;splunk btool props list logtype&lt;/CODE&gt; returns nothing.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 16:02:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-logtype-source-type-defined/m-p/303482#M57303</guid>
      <dc:creator>DUThibault</dc:creator>
      <dc:date>2017-11-24T16:02:35Z</dc:date>
    </item>
    <item>
      <title>Re: Where is the logtype source type defined?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-logtype-source-type-defined/m-p/303483#M57304</link>
      <description>&lt;P&gt;I've now scoured the instance's &lt;CODE&gt;props.conf&lt;/CODE&gt; and &lt;CODE&gt;inputs.conf&lt;/CODE&gt; as well as the forwarder's, and I found &lt;CODE&gt;sourcetype = logtype&lt;/CODE&gt; in &lt;CODE&gt;/opt/splunkforwarder/etc/apps/search/local/inputs.conf&lt;/CODE&gt;. This seems to be an artefact of how I first set up the forwarder (you can do &lt;CODE&gt;splunk add monitor&lt;/CODE&gt; on the forwarder's system or you can configure the monitor from the Splunk instance, using Splunk Web; I should have done just the latter). Sure enough, stopping the forwarder, commenting out the &lt;CODE&gt;sourcetype&lt;/CODE&gt; assignation and restarting the forwarder resulted in the &lt;CODE&gt;sourcetype&lt;/CODE&gt; becoming &lt;CODE&gt;linux_audit&lt;/CODE&gt;. Mystery solved!&lt;/P&gt;</description>
      <pubDate>Fri, 24 Nov 2017 17:20:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-logtype-source-type-defined/m-p/303483#M57304</guid>
      <dc:creator>DUThibault</dc:creator>
      <dc:date>2017-11-24T17:20:34Z</dc:date>
    </item>
    <item>
      <title>Re: Where is the logtype source type defined?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-logtype-source-type-defined/m-p/303484#M57305</link>
      <description>&lt;P&gt;OK, to set your sourcetype to &lt;CODE&gt;automatic&lt;/CODE&gt;, you don't actually set your sourcetype at all, just leave completely out of your &lt;CODE&gt;inputs.conf&lt;/CODE&gt; stanza definition.  If you truly set &lt;CODE&gt;sourcetype=automatic&lt;/CODE&gt;, then I would have expected that your &lt;CODE&gt;sourcetype&lt;/CODE&gt; value would literally be the literal string &lt;CODE&gt;automatic&lt;/CODE&gt;.  I am unsure of how it could have come to be the literal string.&lt;/P&gt;

&lt;P&gt;But let's back up.  It is a generally poor practice to allow Splunk to decide what your sourcetypes are (should be).  If you are going to start there, then turn it on, dump everything to a disposable index (like &lt;CODE&gt;main&lt;/CODE&gt;) and then double-check everything.  In all likelihood, it isn't going to tell you anything that you either didn't already know or wouldn't have immediately realized by glancing at your data.  In any case, for *NIX files under &lt;CODE&gt;/var/log/&lt;/CODE&gt;, splunk should do a find job of sourcetyping, if you set nothing at all.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2017 01:16:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-logtype-source-type-defined/m-p/303484#M57305</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2017-11-26T01:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: Where is the logtype source type defined?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-logtype-source-type-defined/m-p/303485#M57306</link>
      <description>&lt;P&gt;To sum up, any offending sourcetype will probably be caused by a &lt;CODE&gt;sourcetype = &amp;lt;offending_type&amp;gt;&lt;/CODE&gt; stanza in &lt;CODE&gt;[forwarding_system]/opt/splunkforwarder/etc/apps/search/local/inputs.conf&lt;/CODE&gt;. Comment out or delete the line (taking care to stop the forwarder before doing the edit, and restarting it afterwards), and the &lt;CODE&gt;sourcetype&lt;/CODE&gt; will revert to &lt;CODE&gt;automatic&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Nov 2017 19:04:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Where-is-the-logtype-source-type-defined/m-p/303485#M57306</guid>
      <dc:creator>DUThibault</dc:creator>
      <dc:date>2017-11-28T19:04:16Z</dc:date>
    </item>
  </channel>
</rss>

