<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: log parsing failing across multiple sourcetypes in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/log-parsing-failing-across-multiple-sourcetypes/m-p/686925#M10161</link>
    <description>&lt;P&gt;My post can be disregarded,&amp;nbsp; simple misinformation and not checking what/where people were running their field extractions.&amp;nbsp; (App vs Global permissions on Field and Transform extractions). Cheers nontheless and thanks for the pointers&lt;/P&gt;</description>
    <pubDate>Wed, 08 May 2024 20:03:50 GMT</pubDate>
    <dc:creator>alemack</dc:creator>
    <dc:date>2024-05-08T20:03:50Z</dc:date>
    <item>
      <title>log parsing failing across multiple sourcetypes</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/log-parsing-failing-across-multiple-sourcetypes/m-p/686054#M10151</link>
      <description>&lt;P&gt;Hi folks,&amp;nbsp; our field parsing/extraction has broken across all sourcetypes (nginx, log4j, aws:elb's, fix,custom formats as well). The most recent infra event we had was an increase of file storage over a month ago.&amp;nbsp; If our error were related to a single sourcetype I would assume I have to review my props.conf file for the associated app and sourcetype,but in this case it appears something more systemic is occurring.&lt;/P&gt;&lt;P&gt;As someone with limited knowledge of splunk admin,where can I look to narrow my search to the root cause?&amp;nbsp; Trying to RTFM, and am familiar with the "general" log structure but not sure exactly what I'm looking for. (an error/exception on restart directly calling out a props.conf file? An index related exception? idk) Would btool help me confirm if my props.conf files are correctly loading? Is there something would indicate a failure of log parsing?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Splunk Enterprise single-instance 9.2.0.1 on an 8 Core 32GB instance&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;//A&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2024 12:13:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/log-parsing-failing-across-multiple-sourcetypes/m-p/686054#M10151</guid>
      <dc:creator>alemack</dc:creator>
      <dc:date>2024-05-01T12:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: log parsing failing across multiple sourcetypes</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/log-parsing-failing-across-multiple-sourcetypes/m-p/686083#M10152</link>
      <description>&lt;P&gt;&lt;SPAN&gt;It could any number of things. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If this was working before - what changed is what you want to find out first and work out where the problem is. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I guess if it was working before the props/transforms has either change, overwritten, or removed. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Has someone removed the props/transforms apps that those sourcetypes belong to from /opt/splunk/etc/apps. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can check by starting here to find out where those sourcetypes live: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/opt/splunk/bin/splunk btool props list --debug &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;/opt/splunk/bin/splunk btool transforms list --debug&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2024 15:53:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/log-parsing-failing-across-multiple-sourcetypes/m-p/686083#M10152</guid>
      <dc:creator>deepakc</dc:creator>
      <dc:date>2024-05-01T15:53:49Z</dc:date>
    </item>
    <item>
      <title>Re: log parsing failing across multiple sourcetypes</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/log-parsing-failing-across-multiple-sourcetypes/m-p/686925#M10161</link>
      <description>&lt;P&gt;My post can be disregarded,&amp;nbsp; simple misinformation and not checking what/where people were running their field extractions.&amp;nbsp; (App vs Global permissions on Field and Transform extractions). Cheers nontheless and thanks for the pointers&lt;/P&gt;</description>
      <pubDate>Wed, 08 May 2024 20:03:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/log-parsing-failing-across-multiple-sourcetypes/m-p/686925#M10161</guid>
      <dc:creator>alemack</dc:creator>
      <dc:date>2024-05-08T20:03:50Z</dc:date>
    </item>
  </channel>
</rss>

