All Apps and Add-ons

Why is the Splunk App for Unix and Linux generating multiple "yum" source types?

aferone
Builder

I turned on monitoring of /var/log, and when it gets to /var/log/yum.log, I am getting 3 different yum source types for my different systems. All systems are the same Linux flavor.

yum
yum-2
yum-too_small

This is messing with my field extractions.

What is causing this behavior?

Thanks.

sudosplunk
Motivator

If sourcetype is not explicitly defined in .conf files (inputs, props or transforms), splunk will automatically use the logfile name segment as sourcetype name. You can overwrite this by defining configs and settings in local directory inside the app.

0 Karma

aferone
Builder

I guess I assumed that by using the Linux T/A, I wouldn't have to worry about quarks like this?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

From Raw Data to Executive-Ready Stories, Faster

Build Data Stories for Every Audience  A dashboard is rarely just a dashboard. It might be the view an ...

Guided Onboarding with Auto-schema Is Now Generally Available

  We are excited to announce the General Availability of Guided Onboarding with Auto-Schematization ...

ATTENTION: We’re Moving! (AGAIN!)

The Splunk Community Slack is undergoing a system migration to keep our workspace secure and ...