All Apps and Add-ons

Why is the Splunk App for Unix and Linux generating multiple "yum" source types?

aferone
Builder

I turned on monitoring of /var/log, and when it gets to /var/log/yum.log, I am getting 3 different yum source types for my different systems. All systems are the same Linux flavor.

yum
yum-2
yum-too_small

This is messing with my field extractions.

What is causing this behavior?

Thanks.

sudosplunk
Motivator

If sourcetype is not explicitly defined in .conf files (inputs, props or transforms), splunk will automatically use the logfile name segment as sourcetype name. You can overwrite this by defining configs and settings in local directory inside the app.

0 Karma

aferone
Builder

I guess I assumed that by using the Linux T/A, I wouldn't have to worry about quarks like this?

0 Karma
Get Updates on the Splunk Community!

New Release | Splunk Cloud Platform 10.1.2507

Hello Splunk Community!We are thrilled to announce the General Availability of Splunk Cloud Platform 10.1.2507 ...

🌟 From Audit Chaos to Clarity: Welcoming Audit Trail v2

🗣 You Spoke, We Listened  Audit Trail v2 wasn’t written in isolation—it was shaped by your voices.  In ...

Splunk New Course Releases for a Changing World

Every day, the world feels like it’s moving faster with new technological breakthroughs, AI innovation, and ...