<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: how can change forwarder sourcetype? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/how-can-we-change-forwarder-sourcetype/m-p/510324#M142909</link>
    <description>&lt;P&gt;splunk 8.0.4.1, forwarder 7.0&lt;/P&gt;&lt;P&gt;ㅡㅡㅡ&lt;/P&gt;&lt;P&gt;inputs.conf&lt;/P&gt;&lt;P&gt;[monitor:///home/splunk/logdownload/mail/*/*.csv]&lt;/P&gt;&lt;P&gt;host:0.0.0.0&lt;/P&gt;&lt;P&gt;disabled=false&lt;/P&gt;&lt;P&gt;index=mail&lt;/P&gt;&lt;P&gt;soure=csv&lt;/P&gt;&lt;P&gt;sourcetyep=forwarder_mail&lt;/P&gt;&lt;P&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[monitor:///home/splunk/logdownload/wk/*/*http*.csv]&lt;/P&gt;&lt;P&gt;host:0.0.0.0&lt;/P&gt;&lt;P&gt;disabled=false&lt;/P&gt;&lt;P&gt;index=web&lt;/P&gt;&lt;P&gt;soure=csv&lt;/P&gt;&lt;P&gt;sourcetyep=forwarder_http&lt;/P&gt;&lt;P&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[monitor:///home/splunk/logdownload/wk/*/*netapps*.csv]&lt;/P&gt;&lt;P&gt;host:0.0.0.0&lt;/P&gt;&lt;P&gt;disabled=false&lt;/P&gt;&lt;P&gt;index=web&lt;/P&gt;&lt;P&gt;soure=csv&lt;/P&gt;&lt;P&gt;sourcetyep=forwarder_app&lt;/P&gt;&lt;P&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;ㅡㅡㅡ&lt;/P&gt;&lt;P&gt;./splunk btool inpus list --debug, No problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for reply&lt;/P&gt;</description>
    <pubDate>Wed, 22 Jul 2020 01:42:24 GMT</pubDate>
    <dc:creator>lifekis</dc:creator>
    <dc:date>2020-07-22T01:42:24Z</dc:date>
    <item>
      <title>how can we change forwarder sourcetype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-can-we-change-forwarder-sourcetype/m-p/510316#M142907</link>
      <description>&lt;P&gt;I have a problem with parsing, so I want to change the sourcetype.&lt;/P&gt;
&lt;P&gt;ex) index=A sourcetype=A&amp;nbsp; →&amp;nbsp; index=A sourcetype=B&lt;/P&gt;
&lt;P&gt;I am using forwarder and restarted after changing sourcetype in inputs.conf.&lt;/P&gt;
&lt;P&gt;However, the log flows into the existing sourcetype.&lt;BR /&gt;How can I solve it?&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 03:42:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-can-we-change-forwarder-sourcetype/m-p/510316#M142907</guid>
      <dc:creator>lifekis</dc:creator>
      <dc:date>2020-07-23T03:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: how can change forwarder sourcetype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-can-we-change-forwarder-sourcetype/m-p/510319#M142908</link>
      <description>&lt;P&gt;Hi! Can you please share more details, like Splunk version and full data path to indexer?&lt;/P&gt;&lt;P&gt;Is this Universal Forwarder to Indexer?&lt;/P&gt;&lt;P&gt;Can you try&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;./splunk btool inputs list --debug&lt;/LI-CODE&gt;&lt;P&gt;and confirm the forwarder sees your changes?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 01:17:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-can-we-change-forwarder-sourcetype/m-p/510319#M142908</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2020-07-22T01:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: how can change forwarder sourcetype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-can-we-change-forwarder-sourcetype/m-p/510324#M142909</link>
      <description>&lt;P&gt;splunk 8.0.4.1, forwarder 7.0&lt;/P&gt;&lt;P&gt;ㅡㅡㅡ&lt;/P&gt;&lt;P&gt;inputs.conf&lt;/P&gt;&lt;P&gt;[monitor:///home/splunk/logdownload/mail/*/*.csv]&lt;/P&gt;&lt;P&gt;host:0.0.0.0&lt;/P&gt;&lt;P&gt;disabled=false&lt;/P&gt;&lt;P&gt;index=mail&lt;/P&gt;&lt;P&gt;soure=csv&lt;/P&gt;&lt;P&gt;sourcetyep=forwarder_mail&lt;/P&gt;&lt;P&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[monitor:///home/splunk/logdownload/wk/*/*http*.csv]&lt;/P&gt;&lt;P&gt;host:0.0.0.0&lt;/P&gt;&lt;P&gt;disabled=false&lt;/P&gt;&lt;P&gt;index=web&lt;/P&gt;&lt;P&gt;soure=csv&lt;/P&gt;&lt;P&gt;sourcetyep=forwarder_http&lt;/P&gt;&lt;P&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[monitor:///home/splunk/logdownload/wk/*/*netapps*.csv]&lt;/P&gt;&lt;P&gt;host:0.0.0.0&lt;/P&gt;&lt;P&gt;disabled=false&lt;/P&gt;&lt;P&gt;index=web&lt;/P&gt;&lt;P&gt;soure=csv&lt;/P&gt;&lt;P&gt;sourcetyep=forwarder_app&lt;/P&gt;&lt;P&gt;crcSalt=&amp;lt;SOURCE&amp;gt;&lt;/P&gt;&lt;P&gt;ㅡㅡㅡ&lt;/P&gt;&lt;P&gt;./splunk btool inpus list --debug, No problem.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for reply&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 01:42:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-can-we-change-forwarder-sourcetype/m-p/510324#M142909</guid>
      <dc:creator>lifekis</dc:creator>
      <dc:date>2020-07-22T01:42:24Z</dc:date>
    </item>
    <item>
      <title>Re: how can change forwarder sourcetype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-can-we-change-forwarder-sourcetype/m-p/510325#M142910</link>
      <description>&lt;P&gt;sourcetype is mispelled - "sourceteyp". splunk is likely ignoring it. can you confirm btool does not show the proper sourcetype set?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 01:52:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-can-we-change-forwarder-sourcetype/m-p/510325#M142910</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2020-07-22T01:52:59Z</dc:date>
    </item>
    <item>
      <title>Re: how can change forwarder sourcetype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-can-we-change-forwarder-sourcetype/m-p/510326#M142911</link>
      <description>&lt;P&gt;It's a typo and already checked&amp;nbsp;sourcetype set..&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 01:52:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-can-we-change-forwarder-sourcetype/m-p/510326#M142911</guid>
      <dc:creator>lifekis</dc:creator>
      <dc:date>2020-07-22T01:52:55Z</dc:date>
    </item>
    <item>
      <title>Re: how can change forwarder sourcetype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-can-we-change-forwarder-sourcetype/m-p/510327#M142912</link>
      <description>&lt;P&gt;what sourcetype are you receiving? is it being overridden at the indexer?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 01:55:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-can-we-change-forwarder-sourcetype/m-p/510327#M142912</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2020-07-22T01:55:21Z</dc:date>
    </item>
    <item>
      <title>Re: how can change forwarder sourcetype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-can-we-change-forwarder-sourcetype/m-p/510332#M142913</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="img.png" style="width: 924px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/9810i43EBB067A95D0CF7/image-size/large?v=v2&amp;amp;px=999" role="button" title="img.png" alt="img.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 02:11:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-can-we-change-forwarder-sourcetype/m-p/510332#M142913</guid>
      <dc:creator>lifekis</dc:creator>
      <dc:date>2020-07-22T02:11:30Z</dc:date>
    </item>
    <item>
      <title>Re: how can change forwarder sourcetype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-can-we-change-forwarder-sourcetype/m-p/510405#M142914</link>
      <description>&lt;P&gt;ok...so the events get picked up and sent to where? any intermediate forwarders in the path to the indexers? what sourcetype are you seeing in the events in splunk UI?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jul 2020 11:25:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-can-we-change-forwarder-sourcetype/m-p/510405#M142914</guid>
      <dc:creator>mattymo</dc:creator>
      <dc:date>2020-07-22T11:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: how can change forwarder sourcetype?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/how-can-we-change-forwarder-sourcetype/m-p/510554#M142915</link>
      <description>&lt;P&gt;no&amp;nbsp;&lt;SPAN&gt;intermediate and seeing sourcetype=forwarder.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;still can not change sourcetype T.T&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jul 2020 00:08:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/how-can-we-change-forwarder-sourcetype/m-p/510554#M142915</guid>
      <dc:creator>lifekis</dc:creator>
      <dc:date>2020-07-23T00:08:01Z</dc:date>
    </item>
  </channel>
</rss>

