<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Sourcetype Override in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Sourcetype-Override/m-p/352166#M161248</link>
    <description>&lt;P&gt;I forgot to state that these files sit on a rsyslog server (with a forwarder installed) and we ingest them in via inputs.conf. Will the props and transforms need to be on my indexers? I appreciate your response.&lt;/P&gt;</description>
    <pubDate>Thu, 27 Apr 2017 15:59:25 GMT</pubDate>
    <dc:creator>iatwal</dc:creator>
    <dc:date>2017-04-27T15:59:25Z</dc:date>
    <item>
      <title>Sourcetype Override</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sourcetype-Override/m-p/352164#M161246</link>
      <description>&lt;P&gt;We have around 15 files we're ingesting into Splunk all of them have the same format:&lt;/P&gt;

&lt;P&gt;//logs/TEST/mike/TEST1/syslog.log&lt;BR /&gt;
//logs/PROD/julie/TEST1/auth.log&lt;BR /&gt;
//logs/ACPT/rob/TEST1/mail.log&lt;BR /&gt;
//logs/DEV/frank/TEST1/kern.log&lt;BR /&gt;
//logs/STG/rick/TEST1/debug.log&lt;BR /&gt;
//logs/STUFF/ken/TEST1/messages.log&lt;/P&gt;

&lt;P&gt;We would like to change the sourcetype of the names as they come in.  So sourectype should  automatically set to:&lt;/P&gt;

&lt;P&gt;mike&lt;BR /&gt;
julie&lt;BR /&gt;
rob&lt;BR /&gt;
frank&lt;BR /&gt;
rick&lt;BR /&gt;
ken&lt;/P&gt;

&lt;P&gt;Can this be done dynamically via inputs.conf?  Or does this need to happen in props/transforms.conf?  What would my regex look like?  All help is appreciated...&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 14:56:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sourcetype-Override/m-p/352164#M161246</guid>
      <dc:creator>iatwal</dc:creator>
      <dc:date>2017-04-27T14:56:28Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype Override</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sourcetype-Override/m-p/352165#M161247</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;To do this &lt;EM&gt;dynamically&lt;/EM&gt; you would use props.confs and transforms.conf using the following code:&lt;/P&gt;

&lt;P&gt;props.conf:&lt;BR /&gt;
&lt;CODE&gt;TRANSFORMS-change_sourcetype = change_sourcetype&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;EDIT: Please excuse the below formatting; I couldn't get the line breaks to work.&lt;/P&gt;

&lt;P&gt;transforms.conf:&lt;BR /&gt;
&lt;CODE&gt;[change_sourcetype]&lt;BR /&gt;
REGEX = (?U)\/\/logs\/\S+\/(\S+)\/&lt;BR /&gt;
FORMAT = sourcetype::$1&lt;BR /&gt;
DEST_KEY = MetaData:Sourcetype&lt;BR /&gt;
SOURCE_KEY=source&lt;BR /&gt;
&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;Splunk will need to be restarted for the changes to take affect.&lt;/P&gt;

&lt;P&gt;I've not tested it but it should work. Let me know if you have any issues.&lt;/P&gt;

&lt;P&gt;Also, if they all have the same format then I'd recommend that they all share the same sourcetype. Have you considered using a different field? This would be done using a search time extraction.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 15:28:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sourcetype-Override/m-p/352165#M161247</guid>
      <dc:creator>hhGA</dc:creator>
      <dc:date>2017-04-27T15:28:47Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype Override</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sourcetype-Override/m-p/352166#M161248</link>
      <description>&lt;P&gt;I forgot to state that these files sit on a rsyslog server (with a forwarder installed) and we ingest them in via inputs.conf. Will the props and transforms need to be on my indexers? I appreciate your response.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 15:59:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sourcetype-Override/m-p/352166#M161248</guid>
      <dc:creator>iatwal</dc:creator>
      <dc:date>2017-04-27T15:59:25Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype Override</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sourcetype-Override/m-p/352167#M161249</link>
      <description>&lt;P&gt;Hi Iatwal,&lt;/P&gt;

&lt;P&gt;If the rsyslog server is using a universal forwarder then you will have to use the props.conf and transforms.conf on your indexer(s).&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 16:03:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sourcetype-Override/m-p/352167#M161249</guid>
      <dc:creator>hhGA</dc:creator>
      <dc:date>2017-04-27T16:03:51Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype Override</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sourcetype-Override/m-p/352168#M161250</link>
      <description>&lt;P&gt;Another question, what does &lt;/P&gt;

&lt;P&gt;sourcetype::AIDX&lt;/P&gt;

&lt;P&gt;The AIDX mean?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 16:25:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sourcetype-Override/m-p/352168#M161250</guid>
      <dc:creator>iatwal</dc:creator>
      <dc:date>2017-04-27T16:25:16Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype Override</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sourcetype-Override/m-p/352169#M161251</link>
      <description>&lt;P&gt;Another question, what does &lt;/P&gt;

&lt;P&gt;sourcetype::AIDX&lt;/P&gt;

&lt;P&gt;The AIDX mean?&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 16:26:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sourcetype-Override/m-p/352169#M161251</guid>
      <dc:creator>iatwal</dc:creator>
      <dc:date>2017-04-27T16:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype Override</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sourcetype-Override/m-p/352170#M161252</link>
      <description>&lt;P&gt;Apologies, this was left over from my original conf file. I have corrected the original post.&lt;/P&gt;

&lt;P&gt;$1 (the correct value) references the first capture group of the regex.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 17:05:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sourcetype-Override/m-p/352170#M161252</guid>
      <dc:creator>hhGA</dc:creator>
      <dc:date>2017-04-27T17:05:46Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype Override</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sourcetype-Override/m-p/352171#M161253</link>
      <description>&lt;P&gt;so I'm struggling with the REGEX, mind helping here as we're very weak in it.&lt;/P&gt;

&lt;P&gt;Do you mind messing with this, we're looking to make the profile_api our sourcetype...&lt;/P&gt;

&lt;P&gt;&lt;A href="https://regex101.com/r/GYYFmL/5"&gt;https://regex101.com/r/GYYFmL/5&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 17:10:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sourcetype-Override/m-p/352171#M161253</guid>
      <dc:creator>iatwal</dc:creator>
      <dc:date>2017-04-27T17:10:58Z</dc:date>
    </item>
    <item>
      <title>Re: Sourcetype Override</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Sourcetype-Override/m-p/352172#M161254</link>
      <description>&lt;P&gt;&lt;CODE&gt;(?U)\/\S+\/\S+\/(?&amp;lt;sourcetype&amp;gt;.+)\/&lt;/CODE&gt; should work.&lt;/P&gt;

&lt;P&gt;I noticed that your regex101 was set to python. Splunk uses pcre regex for extractions.&lt;/P&gt;

&lt;P&gt;I have missed &lt;CODE&gt;SOURCE_KEY=source&lt;/CODE&gt; from the transforms.conf in my original answer which has now been updated.&lt;/P&gt;</description>
      <pubDate>Thu, 27 Apr 2017 17:35:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Sourcetype-Override/m-p/352172#M161254</guid>
      <dc:creator>hhGA</dc:creator>
      <dc:date>2017-04-27T17:35:55Z</dc:date>
    </item>
  </channel>
</rss>

