<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about Inputs.conf in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530812#M89320</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/162683"&gt;@zekiramhi&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Is the user that runs Splunk (I guess "splunk") able to read the files in the monitoring stanza?&lt;/P&gt;&lt;P&gt;Sourcetype is not mandatory (but recommended). Per Documentation:&amp;nbsp;&lt;BR /&gt;&lt;EM&gt;"If not set, the indexer analyzes the data and chooses a source type."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;BR&lt;BR /&gt;Ralph&lt;/P&gt;</description>
    <pubDate>Wed, 25 Nov 2020 13:14:42 GMT</pubDate>
    <dc:creator>rnowitzki</dc:creator>
    <dc:date>2020-11-25T13:14:42Z</dc:date>
    <item>
      <title>Question about Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530811#M89319</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have made a new app under deployment apps with the following inputs.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[monitor:///root/something/something/something/something/]
index = test
whitelist=console-202[\S\s]+\.log$&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;whitelist is written to input filenames such as console-2020-06-02.log etc&lt;/P&gt;&lt;P&gt;&amp;nbsp;I have not created any sourcetype for the index, so I do not have a props.conf file on the deployment app, neither on the searchheads. I have reloaded the server class that is linked to the host and app but I do not see any attempts to monitor the path I have given on the following spl query:&lt;/P&gt;&lt;P&gt;"index=_internal sourcetype=splunkd *something*"&lt;/P&gt;&lt;P&gt;Am I missing something on the inputs.conf? Am I forced to put a sourcetype? Cant I create my own custom sourcetpe via the gui or do I have to create a props and transforms conf for a sourcetype that does not exist?&lt;/P&gt;&lt;P&gt;Any help is appreciated,&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 13:01:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530811#M89319</guid>
      <dc:creator>zekiramhi</dc:creator>
      <dc:date>2020-11-25T13:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530812#M89320</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/162683"&gt;@zekiramhi&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Is the user that runs Splunk (I guess "splunk") able to read the files in the monitoring stanza?&lt;/P&gt;&lt;P&gt;Sourcetype is not mandatory (but recommended). Per Documentation:&amp;nbsp;&lt;BR /&gt;&lt;EM&gt;"If not set, the indexer analyzes the data and chooses a source type."&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;BR&lt;BR /&gt;Ralph&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 13:14:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530812#M89320</guid>
      <dc:creator>rnowitzki</dc:creator>
      <dc:date>2020-11-25T13:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530814#M89321</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Yes, I have given specific rights for the responsible user just as I have with my previous deployment app which is working.&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 13:26:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530814#M89321</guid>
      <dc:creator>zekiramhi</dc:creator>
      <dc:date>2020-11-25T13:26:53Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530817#M89323</link>
      <description>&lt;P&gt;Is the app in the serverclass configured to restart the forwarder?&lt;BR /&gt;&lt;BR /&gt;(just checking the easy/obvious stuff &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; )&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 13:35:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530817#M89323</guid>
      <dc:creator>rnowitzki</dc:creator>
      <dc:date>2020-11-25T13:35:32Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530820#M89324</link>
      <description>&lt;P&gt;Every input should have a sourcetype associated with it and every sourcetype should have a props.conf stanza.&amp;nbsp; This keeps Splunk from having to guess about how to ingest your data and possibly getting it wrong.&amp;nbsp; You can create a sourcetype in the UI at Settings-&amp;gt;Source types-&amp;gt;New Source Type.&lt;/P&gt;&lt;P&gt;When you created the new app did you specify the Restart Splunkd option?&amp;nbsp; If not, then the inputs.conf has not taken effect.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 13:48:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530820#M89324</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-25T13:48:44Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530833#M89329</link>
      <description>&lt;P&gt;Maybe because I have never created a sourcetype for this index, is the reason it is not accepting to monitor this path. My main goal was to have Splunk ingest the data into Splunk and then create a Sourcetype for the incoming log on the index via the gui.&lt;/P&gt;&lt;P&gt;How I go about doing my sourcetype is the following:&lt;/P&gt;&lt;P&gt;1. Place the log sample on a test server via Add Data &amp;gt; Upload&amp;nbsp;&lt;/P&gt;&lt;P&gt;2. Check if any of the pretrained sourcetypes produce a healthy result, which in this case they havent. So I proceeded to write my own regex for the key value pairs&lt;/P&gt;&lt;P&gt;3. Here lies the main question, now should I just copy the Avanced Settings "Copy to Clippboard" which I am pleased with how it has extracted the time and split the events as I want but the thing is it has set the sourcetype as&amp;nbsp;[ __auto__learned__ ]&amp;nbsp; which I dont think I should change for the events to extract the time automatically.&lt;/P&gt;&lt;P&gt;So now do I create a props.conf with&amp;nbsp; [ __auto__learned__ ]&amp;nbsp;and then reload the serverclass for the logs to flow? (if I go this path do I name the sourcetype to : [ __auto__learned__ ]&amp;nbsp;in inputs.conf?) or can I just set the sourcetype to some dummy name in inputs.conf that does not exist in which I create via gui after the log arrives?&lt;/P&gt;&lt;P&gt;Apologies for the long explanation, but hopefully I have made myself clear&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 14:18:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530833#M89329</guid>
      <dc:creator>zekiramhi</dc:creator>
      <dc:date>2020-11-25T14:18:50Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530834#M89330</link>
      <description>&lt;P&gt;Yes, I have forgotten to do so but I have applied and reloaded the serverclass with no changes unfortunately &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thank you for the suggestion &lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 14:22:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530834#M89330</guid>
      <dc:creator>zekiramhi</dc:creator>
      <dc:date>2020-11-25T14:22:02Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530837#M89331</link>
      <description>&lt;P&gt;Once you have used the Add Data wizard to process a sample data file and are happy with the results, click the Save As button to save your settings as a new sourcetype with a name you specify.&amp;nbsp; Put that same name in the inputs.conf file.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 14:27:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530837#M89331</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-25T14:27:09Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530862#M89334</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have done as you said, and do see the logs that I want being ingested via&lt;/P&gt;&lt;P&gt;&lt;SPAN class="t h"&gt;INFO&lt;/SPAN&gt; &lt;SPAN class="t"&gt;LicenseUsage&lt;/SPAN&gt; &lt;SPAN class="t"&gt;-&lt;/SPAN&gt; &lt;SPAN class="t"&gt;type=Usage.. Logs,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;But I do not see the logs when I try to search for the index or sourcetype, is there anything I am supposed to check?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 17:03:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530862#M89334</guid>
      <dc:creator>zekiramhi</dc:creator>
      <dc:date>2020-11-25T17:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530885#M89337</link>
      <description>&lt;P&gt;Re-run your &lt;FONT face="courier new,courier"&gt;&lt;SPAN class="t h"&gt;INFO&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;LicenseUsage&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="t"&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN class="t"&gt;&lt;FONT face="courier new,courier"&gt;type=Usage.. Logs&lt;/FONT&gt;&amp;nbsp;&lt;/SPAN&gt;search in Verbose Mode.&amp;nbsp; Check the index and sourcetype fields in the events returned.&amp;nbsp; Use those values when you search by index or sourcetype.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Nov 2020 20:25:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530885#M89337</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-11-25T20:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: Question about Inputs.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530940#M89344</link>
      <description>&lt;P&gt;It was still in the process of injesting, after checking for all time I was able to see my logs. Many Thanks &lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Nov 2020 06:09:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Question-about-Inputs-conf/m-p/530940#M89344</guid>
      <dc:creator>zekiramhi</dc:creator>
      <dc:date>2020-11-26T06:09:35Z</dc:date>
    </item>
  </channel>
</rss>

