<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Source Override in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507491#M86367</link>
    <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sourcetype has no other use. I'm in fact trying to create an example to demonstrate sourcetype override. Works fine with monitored inputs but scripted inputs giving problems.&lt;/P&gt;&lt;P&gt;Still no luck. I've used the original sourcetype i. e "performance" but no change at all.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 06 Jul 2020 07:48:57 GMT</pubDate>
    <dc:creator>nabeel652</dc:creator>
    <dc:date>2020-07-06T07:48:57Z</dc:date>
    <item>
      <title>Sourcetype Override</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507467#M86356</link>
      <description>&lt;P&gt;I have a deployed a scripted input with source=perfmon_script that gets server and workstation data.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in props.conf I have:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[source::perfmon_script]
TRANSFORMS-changesourcetype = sourcetype_new&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;in transforms.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[sourcetype_new]
REGEX = .
FORMAT = sourcetype::somesrctype
DEST_KEY = MetaData::Sourcetype&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sourcetype not changing. What am I doing wrong?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 03:02:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507467#M86356</guid>
      <dc:creator>nabeel652</dc:creator>
      <dc:date>2020-07-07T03:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: Source Override</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507469#M86357</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/48579"&gt;@nabeel652&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;what's the wrong behavior?&lt;/P&gt;&lt;P&gt;Anyway, to have as sourcetype you have to use a different FORMAT:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 06:11:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507469#M86357</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-06T06:11:12Z</dc:date>
    </item>
    <item>
      <title>Re: Source Override</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507470#M86358</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;A href="https://community.splunk.com/t5/user/viewprofilepage/user-id/48579" target="_blank"&gt;@nabeel652&lt;/A&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;what's the wrong behavior?&lt;/P&gt;&lt;P&gt;Anyway, to have as sourcetype &lt;SPAN&gt;perfmon:srv or perfmon:ws&amp;nbsp;&lt;/SPAN&gt;you have to use a different FORMAT:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;FORMAT = perfmon:$1&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 06:13:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507470#M86358</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-06T06:13:20Z</dc:date>
    </item>
    <item>
      <title>Re: Source Override</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507471#M86359</link>
      <description>&lt;P&gt;It's simply not working &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 06:15:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507471#M86359</guid>
      <dc:creator>nabeel652</dc:creator>
      <dc:date>2020-07-06T06:15:08Z</dc:date>
    </item>
    <item>
      <title>Re: Source Override</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507472#M86360</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, that's correct. However, my transform is not working at all&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 06:18:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507472#M86360</guid>
      <dc:creator>nabeel652</dc:creator>
      <dc:date>2020-07-06T06:18:04Z</dc:date>
    </item>
    <item>
      <title>Re: Source Override</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507473#M86361</link>
      <description>&lt;P&gt;HI&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/48579"&gt;@nabeel652&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;yes, but in which way: remain the original sourcetype? or override both the the sourcetype with the same? or what else?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 06:20:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507473#M86361</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-06T06:20:21Z</dc:date>
    </item>
    <item>
      <title>Re: Source Override</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507474#M86362</link>
      <description>&lt;P&gt;The original sourcetype remains&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 06:21:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507474#M86362</guid>
      <dc:creator>nabeel652</dc:creator>
      <dc:date>2020-07-06T06:21:40Z</dc:date>
    </item>
    <item>
      <title>Re: Source Override</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507475#M86363</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some more details:&lt;BR /&gt;I've deployed the scripted input on one of my heavy forwarders. I've tried this transform on the same heavy forwarder as well as the indexer but fails to change the sourcetype to new one.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 04:10:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507475#M86363</guid>
      <dc:creator>nabeel652</dc:creator>
      <dc:date>2020-07-07T04:10:37Z</dc:date>
    </item>
    <item>
      <title>Re: Source Override</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507477#M86364</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/48579"&gt;@nabeel652&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;debug the problem:&amp;nbsp;&lt;/P&gt;&lt;P&gt;use a static overriding to understand if the problem is the transformation:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[sourcetype_override]
REGEX = .
FORMAT = sourcetype::perfmon
DEST_KEY = MetaData:Sourcetype&lt;/LI-CODE&gt;&lt;P&gt;If this transformation runs the problem is in the original transformation itself, if it doesn't run the problem is before.&lt;/P&gt;&lt;P&gt;Obviously you restarted Splunk on the HF that you modified, is it correct?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 06:39:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507477#M86364</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-06T06:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: Source Override</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507479#M86365</link>
      <description>&lt;P&gt;Tried that but still not working.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes, I'm restarting Splunk everytime I make changes&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 04:11:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507479#M86365</guid>
      <dc:creator>nabeel652</dc:creator>
      <dc:date>2020-07-07T04:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: Source Override</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507485#M86366</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/48579"&gt;@nabeel652&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;You said that the sourcetype isn't overwritten.&lt;/P&gt;&lt;P&gt;This means that the problem isn't in the transformation, but in the flow.&lt;/P&gt;&lt;P&gt;Only one question: the sourcetype performance that you assign to the script in the inputs.conf, is used only in this case or has another use?&lt;/P&gt;&lt;P&gt;in other words, try to modify your configuration in this way (I used performance_test but you can use the one you like):&lt;/P&gt;&lt;P&gt;inputs.conf:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[script://./bin/serverPerformance.py]
disabled=0
sourcetype=performance_test
source = perfmon_script
interval=30&lt;/LI-CODE&gt;&lt;P&gt;props.conf:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[performance_test]
TRANSFORMS-changesourcetype = sourcetype_override&lt;/LI-CODE&gt;&lt;P&gt;transforms.conf:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[sourcetype_override]
REGEX = src\=(srv|ws)\_
FORMAT = sourcetype::perfmon:$1
DEST_KEY = MetaData::Sourcetype&lt;/LI-CODE&gt;&lt;P&gt;in few words, use original sourcetype, instead source for the overriding.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 07:06:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507485#M86366</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-06T07:06:33Z</dc:date>
    </item>
    <item>
      <title>Re: Source Override</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507491#M86367</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sourcetype has no other use. I'm in fact trying to create an example to demonstrate sourcetype override. Works fine with monitored inputs but scripted inputs giving problems.&lt;/P&gt;&lt;P&gt;Still no luck. I've used the original sourcetype i. e "performance" but no change at all.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 07:48:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507491#M86367</guid>
      <dc:creator>nabeel652</dc:creator>
      <dc:date>2020-07-06T07:48:57Z</dc:date>
    </item>
    <item>
      <title>Re: Source Override</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507498#M86368</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/48579"&gt;@nabeel652&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;could you share the inputs,props and transforms you used in the last test?&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 08:32:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507498#M86368</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-06T08:32:28Z</dc:date>
    </item>
    <item>
      <title>Re: Source Override</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507518#M86372</link>
      <description>&lt;P&gt;props.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[performance]
TRANSFORMS-changesourcetype = sourcetype_override&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;transforms.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[sourcetype_override]
REGEX = .
FORMAT = sourcetype::new_srctype
DEST_KEY = MetaData::Sourcetype&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 04:04:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507518#M86372</guid>
      <dc:creator>nabeel652</dc:creator>
      <dc:date>2020-07-07T04:04:51Z</dc:date>
    </item>
    <item>
      <title>Re: Source Override</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507519#M86373</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/48579"&gt;@nabeel652&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;can you confirm that props and transforms are located on Heavy Forwarder?&amp;nbsp;&lt;/P&gt;&lt;P&gt;and that HF was restarted after files updates?&lt;/P&gt;&lt;P&gt;there isn't any addition reasono for the problem.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 10:29:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507519#M86373</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-06T10:29:59Z</dc:date>
    </item>
    <item>
      <title>Re: Source Override</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507520#M86374</link>
      <description>&lt;P&gt;Yep,&lt;/P&gt;&lt;P&gt;All three files inputs.conf, props.conf and transforms.conf is in&lt;/P&gt;&lt;P&gt;/opt/splunk/etc/apps/mycustomapp/local/&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 10:37:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507520#M86374</guid>
      <dc:creator>nabeel652</dc:creator>
      <dc:date>2020-07-06T10:37:11Z</dc:date>
    </item>
    <item>
      <title>Re: Source Override</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507521#M86375</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/48579"&gt;@nabeel652&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;The last try I hint is to put props.conf and transforms.con also on Indexers, but it shouldn't be relevant!&lt;/P&gt;&lt;P&gt;After Open a case to Splunk!&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 10:43:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507521#M86375</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-07-06T10:43:05Z</dc:date>
    </item>
    <item>
      <title>Re: Source Override</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507525#M86376</link>
      <description>&lt;P&gt;No luck &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Will log a case&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jul 2020 11:19:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507525#M86376</guid>
      <dc:creator>nabeel652</dc:creator>
      <dc:date>2020-07-06T11:19:10Z</dc:date>
    </item>
    <item>
      <title>Re: Source Override</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507727#M86409</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Well, what a silly mistake that I've made&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is MetaData:Sourcetype NOT MetaData::Sourcetype&lt;/P&gt;&lt;P&gt;Fixed it and all good!&lt;/P&gt;&lt;P&gt;Thanks anyway for your time and sorry once again for the small typo that caused big hassle&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2020 02:56:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Sourcetype-Override/m-p/507727#M86409</guid>
      <dc:creator>nabeel652</dc:creator>
      <dc:date>2020-07-07T02:56:36Z</dc:date>
    </item>
  </channel>
</rss>

