<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Monitoring same logs for two different sourcetype in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-same-logs-for-two-different-sourcetype/m-p/434478#M75862</link>
    <description>&lt;P&gt;@lakshman239 : Thanks for reply. No we don't have control over logs so can't add anything to distinguish between sourcetype. Both sourcetype having different linebreaking approach, can go under the same sourcetype.&lt;/P&gt;</description>
    <pubDate>Mon, 28 Jan 2019 11:08:21 GMT</pubDate>
    <dc:creator>AKG1_old1</dc:creator>
    <dc:date>2019-01-28T11:08:21Z</dc:date>
    <item>
      <title>Monitoring same logs for two different sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-same-logs-for-two-different-sourcetype/m-p/434476#M75860</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;we are monitoring GC logs and logs could be in two different format.(Conventional GC and G1)&lt;BR /&gt;
Requirement is that if logs are in GC format it goes to GC sourcetype and if G1 then G1 sourcetype.&lt;/P&gt;

&lt;P&gt;One apporach is to upload these logs twice by  setting up 2 different forwarders. but looking for some better approach.&lt;/P&gt;

&lt;P&gt;GC logs are complex so redirecting the logs by identifying the type would be difficult.(using props and transform)&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2019 10:26:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-same-logs-for-two-different-sourcetype/m-p/434476#M75860</guid>
      <dc:creator>AKG1_old1</dc:creator>
      <dc:date>2019-01-28T10:26:59Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring same logs for two different sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-same-logs-for-two-different-sourcetype/m-p/434477#M75861</link>
      <description>&lt;P&gt;Would it be possible to add a change in the logging application to write the logs to 2 diff files [ one for GC and another for G1]?&lt;/P&gt;

&lt;P&gt;If both the events can go to the same sourcetype [ assuming line breaking etc.. is possible], you could we tag them (using eventtypes/tags.conf) to help with your search? would that help?&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2019 10:58:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-same-logs-for-two-different-sourcetype/m-p/434477#M75861</guid>
      <dc:creator>lakshman239</dc:creator>
      <dc:date>2019-01-28T10:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: Monitoring same logs for two different sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Monitoring-same-logs-for-two-different-sourcetype/m-p/434478#M75862</link>
      <description>&lt;P&gt;@lakshman239 : Thanks for reply. No we don't have control over logs so can't add anything to distinguish between sourcetype. Both sourcetype having different linebreaking approach, can go under the same sourcetype.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jan 2019 11:08:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Monitoring-same-logs-for-two-different-sourcetype/m-p/434478#M75862</guid>
      <dc:creator>AKG1_old1</dc:creator>
      <dc:date>2019-01-28T11:08:21Z</dc:date>
    </item>
  </channel>
</rss>

