All Apps and Add-ons

Apply sourcetype on FTP Input (FTP Pull App)

pgylbert
New Member

I have a production equipment storing a log that I can access through FTP. I installed FTP Pull and set up an input and it works OK that far. However, the file format is a bit odd, so simply taking it in is not enough. (It has a special timestamp that Splunk does not interpret correctly out of the box, and there is no header line in the file). I have created a new sourcetype where I configured timestamp format and field names. When I upload the file manually and apply that particular sourcetype, data is indexed properly. I selected this sourcetype in the FTP Input configuration but it does not seem to take effect. The indexed events get this selected sourcetype associated, but the configuration of the sourcetype is not observed, so when the file comes through FTP, it is indexed incorrectly.

Is there a way to enforce the FTP Input to actually apply the configuration of the selected sourcetype?

Thanks in advance for sharing your thoughts or experience with me

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...