<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Need help writing input stanza for maillog in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-writing-input-stanza-for-maillog/m-p/529468#M89193</link>
    <description>&lt;P&gt;I'm having a hard time getting my stanza setup correctly. I basically want to monitor the maillog directories (maillog + maillog-date) and choose the best appropriate sourcetype&lt;/P&gt;&lt;P&gt;However the archive maillog directories aren't coming in&lt;/P&gt;&lt;P&gt;Can someone spin me In the right direction on how to better write this stanza? Please resist the urge to send me a splunk doc link as I've been rummaging through those for a while.. it's not clicking&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone please help me in rewriting a better stanza&lt;/P&gt;&lt;P&gt;[monitor:///var/log]&lt;BR /&gt;Whitelist =(maillog$)&lt;BR /&gt;disabled = false&lt;BR /&gt;sourcetype = maillog&lt;BR /&gt;Index = linux&lt;/P&gt;&lt;P&gt;Currently it's not working where it's pulling in the archive logs. So anything with a date after maillog isn't getting pulled&lt;/P&gt;&lt;P&gt;I think I tried [monitor:///var/log/maillog*] without the whitelist but it isn't working&lt;/P&gt;</description>
    <pubDate>Sun, 15 Nov 2020 19:42:27 GMT</pubDate>
    <dc:creator>Jarohnimo</dc:creator>
    <dc:date>2020-11-15T19:42:27Z</dc:date>
    <item>
      <title>Need help writing input stanza for maillog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-writing-input-stanza-for-maillog/m-p/529468#M89193</link>
      <description>&lt;P&gt;I'm having a hard time getting my stanza setup correctly. I basically want to monitor the maillog directories (maillog + maillog-date) and choose the best appropriate sourcetype&lt;/P&gt;&lt;P&gt;However the archive maillog directories aren't coming in&lt;/P&gt;&lt;P&gt;Can someone spin me In the right direction on how to better write this stanza? Please resist the urge to send me a splunk doc link as I've been rummaging through those for a while.. it's not clicking&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone please help me in rewriting a better stanza&lt;/P&gt;&lt;P&gt;[monitor:///var/log]&lt;BR /&gt;Whitelist =(maillog$)&lt;BR /&gt;disabled = false&lt;BR /&gt;sourcetype = maillog&lt;BR /&gt;Index = linux&lt;/P&gt;&lt;P&gt;Currently it's not working where it's pulling in the archive logs. So anything with a date after maillog isn't getting pulled&lt;/P&gt;&lt;P&gt;I think I tried [monitor:///var/log/maillog*] without the whitelist but it isn't working&lt;/P&gt;</description>
      <pubDate>Sun, 15 Nov 2020 19:42:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-help-writing-input-stanza-for-maillog/m-p/529468#M89193</guid>
      <dc:creator>Jarohnimo</dc:creator>
      <dc:date>2020-11-15T19:42:27Z</dc:date>
    </item>
    <item>
      <title>Re: Need help writing input stanza for maillog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-writing-input-stanza-for-maillog/m-p/529470#M89194</link>
      <description>Have you check permission of files and directories, so your splunk user can read those or are you running splunk as root (security risk)?&lt;BR /&gt;r. Ismo</description>
      <pubDate>Sun, 15 Nov 2020 20:29:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-help-writing-input-stanza-for-maillog/m-p/529470#M89194</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-11-15T20:29:51Z</dc:date>
    </item>
    <item>
      <title>Re: Need help writing input stanza for maillog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-writing-input-stanza-for-maillog/m-p/529472#M89195</link>
      <description>&lt;P&gt;Hi, I do have read permission as other logs are coming in&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please tell me if: maillog&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is the correct sourcetype for /var/log/maillog&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I saw a few choices but it's unclear what's the best to use. Sendmail_syslog I thought looked promising but there I am guessing again&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 15 Nov 2020 21:42:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-help-writing-input-stanza-for-maillog/m-p/529472#M89195</guid>
      <dc:creator>Jarohnimo</dc:creator>
      <dc:date>2020-11-15T21:42:31Z</dc:date>
    </item>
    <item>
      <title>Re: Need help writing input stanza for maillog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-writing-input-stanza-for-maillog/m-p/529474#M89196</link>
      <description>&lt;P&gt;Hey there. Check Splunk's _internal index for any nuggets of info on this issue. This is assuming that the internal logs are being forwarded. If not look at the splunkd.log file on the host that has the input configured.&lt;/P&gt;&lt;P&gt;Splunk btool command may be of use to ensure that this config is even being read or being over ridden somehow. If you are editing the inputs.conf manually make sure that splunkd can read the inputs.conf file.&lt;/P&gt;&lt;P&gt;Just some things that come to mind...&lt;/P&gt;</description>
      <pubDate>Sat, 21 Nov 2020 19:32:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-help-writing-input-stanza-for-maillog/m-p/529474#M89196</guid>
      <dc:creator>brent_weaver</dc:creator>
      <dc:date>2020-11-21T19:32:18Z</dc:date>
    </item>
  </channel>
</rss>

