<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Oracle alert logs in Alerting</title>
    <link>https://community.splunk.com/t5/Alerting/Oracle-alert-logs/m-p/582003#M13406</link>
    <description>&lt;P&gt;Hola, lo conseguiste? como pudiste mandar el log de 'alert' a un índice? Tengo la aplicación&amp;nbsp;&lt;EM&gt;Splunk_TA_oracle&lt;/EM&gt; es un Heavy Forwarder pero no se como recibir datos. Me podrías indicar los pasos?&lt;/P&gt;&lt;P&gt;Muchas gracias y un saludo.&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jan 2022 13:52:45 GMT</pubDate>
    <dc:creator>talonso</dc:creator>
    <dc:date>2022-01-21T13:52:45Z</dc:date>
    <item>
      <title>Oracle alert logs</title>
      <link>https://community.splunk.com/t5/Alerting/Oracle-alert-logs/m-p/29292#M253</link>
      <description>&lt;P&gt;I need to monitor Oracle alert logs and noticed that there are no pretrained sourcetypes for Oracle logs. Do I need to create a custom sourcetype? Can I add these logs to Splunk without defining the log format?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Dec 2011 16:25:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Oracle-alert-logs/m-p/29292#M253</guid>
      <dc:creator>jonathan_lam</dc:creator>
      <dc:date>2011-12-06T16:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: Oracle alert logs</title>
      <link>https://community.splunk.com/t5/Alerting/Oracle-alert-logs/m-p/29293#M254</link>
      <description>&lt;P&gt;You could probably start indexing without too much hassle. You don't need to configure anything, but you could avoid a few problems down the line by ensuring that timestamps and sourcetypes are correct.&lt;/P&gt;

&lt;P&gt;First - create a dummy test index and upload an Oracle Alert file there to check the following:&lt;BR /&gt;
are timestamps recognized correctly?&lt;BR /&gt;
does splunk set a sourcetype name you can live with?&lt;/P&gt;

&lt;P&gt;If not, you'd need to fix this before you start to send the files to the production index.&lt;/P&gt;

&lt;P&gt;This is done in props.conf and inputs.conf, respectively. The inputs.conf deal with things happening during the input phase, so if you have any type of forwarder, you should edit the inputs.conf there. props.conf settings are handled in several phases, but timestamping settings should be configured on the forwarder only if you have a full forwarder. If you have UF or LWF, or no forwarder at all, this is configured on the indexer. &lt;/P&gt;

&lt;P&gt;Some of the following might help you;&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Admin/Inputsconf&lt;/A&gt;&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkcanmonitor"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Data/WhatSplunkcanmonitor&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;hope this helps,&lt;/P&gt;

&lt;P&gt;Kristian&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2011 08:38:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Oracle-alert-logs/m-p/29293#M254</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2011-12-07T08:38:26Z</dc:date>
    </item>
    <item>
      <title>Re: Oracle alert logs</title>
      <link>https://community.splunk.com/t5/Alerting/Oracle-alert-logs/m-p/29294#M255</link>
      <description>&lt;P&gt;Thank you sir. I was able to set up the new sourcetype without any configuration to props.conf but will look into your recommendations.&lt;/P&gt;</description>
      <pubDate>Wed, 07 Dec 2011 14:31:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Oracle-alert-logs/m-p/29294#M255</guid>
      <dc:creator>jonathan_lam</dc:creator>
      <dc:date>2011-12-07T14:31:32Z</dc:date>
    </item>
    <item>
      <title>Re: Oracle alert logs</title>
      <link>https://community.splunk.com/t5/Alerting/Oracle-alert-logs/m-p/29295#M256</link>
      <description>&lt;P&gt;Please mark the question as 'answered' by clicking the check mark (a/o vote up) if you've found this helpful.&lt;/P&gt;

&lt;P&gt;/k&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2011 08:23:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Oracle-alert-logs/m-p/29295#M256</guid>
      <dc:creator>kristian_kolb</dc:creator>
      <dc:date>2011-12-08T08:23:45Z</dc:date>
    </item>
    <item>
      <title>Re: Oracle alert logs</title>
      <link>https://community.splunk.com/t5/Alerting/Oracle-alert-logs/m-p/582003#M13406</link>
      <description>&lt;P&gt;Hola, lo conseguiste? como pudiste mandar el log de 'alert' a un índice? Tengo la aplicación&amp;nbsp;&lt;EM&gt;Splunk_TA_oracle&lt;/EM&gt; es un Heavy Forwarder pero no se como recibir datos. Me podrías indicar los pasos?&lt;/P&gt;&lt;P&gt;Muchas gracias y un saludo.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jan 2022 13:52:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Alerting/Oracle-alert-logs/m-p/582003#M13406</guid>
      <dc:creator>talonso</dc:creator>
      <dc:date>2022-01-21T13:52:45Z</dc:date>
    </item>
  </channel>
</rss>

