<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Several small log files - sourcetype = local-too_small in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Several-small-log-files-sourcetype-local-too-small/m-p/307160#M57877</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I've got a problem with monitoring several log files generated by syslog-ng. There are 50+ switches. I am collecting their logs with a syslog-ng server, generating separate log files for every switch, every day. Some of them send only a few lines so that logs file is small.&lt;BR /&gt;
I can collect all the logs, but I have got an issue with the sourcetype. All (most?) of the small log file has a local-too_small sourcetype instead of syslog, which I configured explicitly. Based on my research and testing, the auto sourcetype can cause this, but I already add the sourcetype. So what I am doing wrong, why the Splunk ignore it?&lt;/P&gt;

&lt;P&gt;inputs.conf:&lt;BR /&gt;
[monitor:///var/log/remotelogs/*/log/]&lt;BR /&gt;
host_segment = 8&lt;BR /&gt;
index = default&lt;BR /&gt;
sourcetype=syslog&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
István&lt;/P&gt;</description>
    <pubDate>Wed, 29 Nov 2017 13:47:31 GMT</pubDate>
    <dc:creator>ikulcsar</dc:creator>
    <dc:date>2017-11-29T13:47:31Z</dc:date>
    <item>
      <title>Several small log files - sourcetype = local-too_small</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Several-small-log-files-sourcetype-local-too-small/m-p/307160#M57877</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;I've got a problem with monitoring several log files generated by syslog-ng. There are 50+ switches. I am collecting their logs with a syslog-ng server, generating separate log files for every switch, every day. Some of them send only a few lines so that logs file is small.&lt;BR /&gt;
I can collect all the logs, but I have got an issue with the sourcetype. All (most?) of the small log file has a local-too_small sourcetype instead of syslog, which I configured explicitly. Based on my research and testing, the auto sourcetype can cause this, but I already add the sourcetype. So what I am doing wrong, why the Splunk ignore it?&lt;/P&gt;

&lt;P&gt;inputs.conf:&lt;BR /&gt;
[monitor:///var/log/remotelogs/*/log/]&lt;BR /&gt;
host_segment = 8&lt;BR /&gt;
index = default&lt;BR /&gt;
sourcetype=syslog&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
István&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2017 13:47:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Several-small-log-files-sourcetype-local-too-small/m-p/307160#M57877</guid>
      <dc:creator>ikulcsar</dc:creator>
      <dc:date>2017-11-29T13:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: Several small log files - sourcetype = local-too_small</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Several-small-log-files-sourcetype-local-too-small/m-p/307161#M57878</link>
      <description>&lt;P&gt;Hi @ikulcsar,&lt;/P&gt;

&lt;P&gt;Can you please check your inputs.conf configuration using btool &lt;CODE&gt;$SPLUNK_HOME/bin/splunk cmd btool inputs --debug list&lt;/CODE&gt; and check whether &lt;CODE&gt;sourcetype=syslog&lt;/CODE&gt; is assigned to your monitor stanza or not? If it is assigned then can you please try to restart splunkforwarder ?&lt;/P&gt;</description>
      <pubDate>Wed, 29 Nov 2017 14:03:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Several-small-log-files-sourcetype-local-too-small/m-p/307161#M57878</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2017-11-29T14:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: Several small log files - sourcetype = local-too_small</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Several-small-log-files-sourcetype-local-too-small/m-p/307162#M57879</link>
      <description>&lt;P&gt;Hi, &lt;BR /&gt;
Thank you for your comment. Here is the output. I modified the monitor definition to be more specific, restart the full server, too. But no change.&lt;/P&gt;

&lt;P&gt;/opt/splunk/etc/system/local/inputs.conf                               [monitor:///var/log/remotelogs/&lt;EM&gt;/log/&lt;/EM&gt;/&lt;EM&gt;/&lt;/EM&gt;]&lt;BR /&gt;
/opt/splunk/etc/system/default/inputs.conf                             _rcvbuf = 1572864&lt;BR /&gt;
/opt/splunk/etc/system/local/inputs.conf                               host = shadow&lt;BR /&gt;
/opt/splunk/etc/system/local/inputs.conf                               host_segment = 8&lt;BR /&gt;
/opt/splunk/etc/system/local/inputs.conf                               index = default&lt;BR /&gt;
/opt/splunk/etc/system/local/inputs.conf                               sourcetype = syslog&lt;/P&gt;

&lt;P&gt;Any other idea?&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
István&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:58:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Several-small-log-files-sourcetype-local-too-small/m-p/307162#M57879</guid>
      <dc:creator>ikulcsar</dc:creator>
      <dc:date>2020-09-29T16:58:42Z</dc:date>
    </item>
    <item>
      <title>Re: Several small log files - sourcetype = local-too_small</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Several-small-log-files-sourcetype-local-too-small/m-p/307163#M57880</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;Finally, I reinstall it from the scratch with Splunk Ent. 7.0, reconfigure the inputs and it works... I can not explain and unfortunately cannot reproduce that behavior... &lt;/P&gt;

&lt;P&gt;Thank you for your kind help.&lt;BR /&gt;
Regards,&lt;BR /&gt;
István&lt;/P&gt;</description>
      <pubDate>Sat, 02 Dec 2017 09:21:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Several-small-log-files-sourcetype-local-too-small/m-p/307163#M57880</guid>
      <dc:creator>ikulcsar</dc:creator>
      <dc:date>2017-12-02T09:21:50Z</dc:date>
    </item>
    <item>
      <title>Re: Several small log files - sourcetype = local-too_small</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Several-small-log-files-sourcetype-local-too-small/m-p/307164#M57881</link>
      <description>&lt;P&gt;Hi, &lt;/P&gt;

&lt;P&gt;Finally, I reinstall it from the scratch with Splunk Ent. 7.0, reconfigure the inputs and it works... I can not explain and unfortunately cannot reproduce that behavior... &lt;/P&gt;

&lt;P&gt;Thank you for your kind help.&lt;BR /&gt;
Regards,&lt;BR /&gt;
István&lt;/P&gt;</description>
      <pubDate>Sat, 02 Dec 2017 09:21:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Several-small-log-files-sourcetype-local-too-small/m-p/307164#M57881</guid>
      <dc:creator>ikulcsar</dc:creator>
      <dc:date>2017-12-02T09:21:50Z</dc:date>
    </item>
  </channel>
</rss>

