<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: inputs configuration and location. in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/inputs-configuration-and-location/m-p/678063#M9885</link>
    <description>&lt;P&gt;inputs.conf is configured on the machine from where the data is forwarded. So it could be on UF,HF,Indexer or even on Search Head if the logs are being forwarded&lt;/P&gt;&lt;P&gt;Sourcetype can be applied on the general section which will be considered if individual sections are not specified&lt;/P&gt;&lt;P&gt;Please have a look at this&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.0/Admin/Wheretofindtheconfigurationfiles" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.0/Admin/Wheretofindtheconfigurationfiles&lt;/A&gt;&amp;nbsp;more detailed information&lt;/P&gt;&lt;P&gt;And also here to have an understanding about the data processing&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Diagrams-of-how-indexing-works-in-the-Splunk-platform-the-Masa/m-p/590781#M103485" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/Diagrams-of-how-indexing-works-in-the-Splunk-platform-the-Masa/m-p/590781#M103485&lt;/A&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;source&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is the name of the file, stream, or other input from which a particular event originates.&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;sourcetype&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;determines how Splunk software processes the incoming data stream into individual events according to the nature of the data.&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In short , /var/log/apache.log is a source and how the source file should be parsed is defined by the sourcetype&amp;nbsp;access_combined&lt;/P&gt;&lt;PRE&gt;&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 20 Feb 2024 12:02:37 GMT</pubDate>
    <dc:creator>renjith_nair</dc:creator>
    <dc:date>2024-02-20T12:02:37Z</dc:date>
    <item>
      <title>inputs configuration and location.</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/inputs-configuration-and-location/m-p/678046#M9884</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;I am confused on which machines I am intended to have my inputs.conf files configured.&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. I am currently operating under the assumption that inputs.conf files are primarily for the indexer is this correct?&lt;/P&gt;&lt;P&gt;2. If I update an inputs.conf file do I need to push the updated file through my deployment server so that the inputs.conf files tied to the applications on the S.U.F reflect in the same changes made on the manager.&lt;/P&gt;&lt;P&gt;a. I have raw xml data populating and I wish to fix this so that it is easier to read... Currently there is no source type in my inputs.conf. I believe applying an appropriate source type in the inputs.conf is the first step to fixing this problem.&amp;nbsp;&lt;/P&gt;&lt;P&gt;b. There are multiple stanzas in inputs.conf. Do I need to apply a source type to each of the stanzas that have to do with sending xml logs or is their a way to apply this change on global scale?&lt;/P&gt;&lt;P&gt;Z. Will someone please explain the difference between source and source type I have read the documentation on the manner and am still uncertain in my understanding.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the help in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2024 09:20:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/inputs-configuration-and-location/m-p/678046#M9884</guid>
      <dc:creator>Mr_Sneed</dc:creator>
      <dc:date>2024-02-20T09:20:25Z</dc:date>
    </item>
    <item>
      <title>Re: inputs configuration and location.</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/inputs-configuration-and-location/m-p/678063#M9885</link>
      <description>&lt;P&gt;inputs.conf is configured on the machine from where the data is forwarded. So it could be on UF,HF,Indexer or even on Search Head if the logs are being forwarded&lt;/P&gt;&lt;P&gt;Sourcetype can be applied on the general section which will be considered if individual sections are not specified&lt;/P&gt;&lt;P&gt;Please have a look at this&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.2.0/Admin/Wheretofindtheconfigurationfiles" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/9.2.0/Admin/Wheretofindtheconfigurationfiles&lt;/A&gt;&amp;nbsp;more detailed information&lt;/P&gt;&lt;P&gt;And also here to have an understanding about the data processing&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Diagrams-of-how-indexing-works-in-the-Splunk-platform-the-Masa/m-p/590781#M103485" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/Diagrams-of-how-indexing-works-in-the-Splunk-platform-the-Masa/m-p/590781#M103485&lt;/A&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;source&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;is the name of the file, stream, or other input from which a particular event originates.&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;UL&gt;&lt;LI&gt;&lt;DIV class=""&gt;The&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;sourcetype&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;determines how Splunk software processes the incoming data stream into individual events according to the nature of the data.&lt;/DIV&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In short , /var/log/apache.log is a source and how the source file should be parsed is defined by the sourcetype&amp;nbsp;access_combined&lt;/P&gt;&lt;PRE&gt;&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2024 12:02:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/inputs-configuration-and-location/m-p/678063#M9885</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2024-02-20T12:02:37Z</dc:date>
    </item>
    <item>
      <title>Re: inputs configuration and location.</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/inputs-configuration-and-location/m-p/678066#M9886</link>
      <description>&lt;P&gt;Thank you for the information. It is very helpful!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Feb 2024 12:15:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/inputs-configuration-and-location/m-p/678066#M9886</guid>
      <dc:creator>Mr_Sneed</dc:creator>
      <dc:date>2024-02-20T12:15:40Z</dc:date>
    </item>
  </channel>
</rss>

