All Apps and Add-ons

Why is the Splunk App for Unix and Linux generating multiple "yum" source types?

aferone
Builder

I turned on monitoring of /var/log, and when it gets to /var/log/yum.log, I am getting 3 different yum source types for my different systems. All systems are the same Linux flavor.

yum
yum-2
yum-too_small

This is messing with my field extractions.

What is causing this behavior?

Thanks.

sudosplunk
Motivator

If sourcetype is not explicitly defined in .conf files (inputs, props or transforms), splunk will automatically use the logfile name segment as sourcetype name. You can overwrite this by defining configs and settings in local directory inside the app.

0 Karma

aferone
Builder

I guess I assumed that by using the Linux T/A, I wouldn't have to worry about quarks like this?

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...