Getting Data In

How do I test sourcetyping before I index

rroberts
Splunk Employee
Splunk Employee

How can I see how Splunk is going to handle a particular dataset BEFORE I actually input? For example: If I monitor a log what sourcetype is splunk going to tag the events with?

Tags (2)
0 Karma
1 Solution

rroberts
Splunk Employee
Splunk Employee

Check the CLI test. From $SPLUNK_HOME/bin Check help for test... ./splunk test help ./splunk test sourcetype

Example:

./splunk test sourcetype /opt/tradelog/trade_entries.log

PROPERTIES OF /opt/log/tradelog/trade_entries.log
Attr:ANNOTATE_PUNCT True
Attr:BREAK_ONLY_BEFORE
Attr:BREAK_ONLY_BEFORE_DATE True
Attr:CHARSET UTF-8
Attr:DATETIME_CONFIG /etc/datetime.xml
Attr:HEADER_MODE
Attr:LEARN_SOURCETYPE true
Attr:LINE_BREAKER_LOOKBEHIND 100
Attr:MAX_DAYS_AGO 2000
Attr:MAX_DAYS_HENCE 2
Attr:MAX_DIFF_SECS_AGO 3600
Attr:MAX_DIFF_SECS_HENCE 604800
Attr:MAX_EVENTS 256
Attr:MAX_TIMESTAMP_LOOKAHEAD 44
Attr:MUST_BREAK_AFTER
Attr:MUST_NOT_BREAK_AFTER
Attr:MUST_NOT_BREAK_BEFORE
Attr:SEGMENTATION indexing
Attr:SEGMENTATION-all full
Attr:SEGMENTATION-inner inner
Attr:SEGMENTATION-outer outer
Attr:SEGMENTATION-raw none
Attr:SEGMENTATION-standard standard
Attr:SHOULD_LINEMERGE False
Attr:TRANSFORMS Attr:TRUNCATE 10000
Attr:is_valid True
Attr:maxDist 100
Attr:sourcetype trade_entries-2

Note attributes including sourcetype.

View solution in original post

0 Karma

rroberts
Splunk Employee
Splunk Employee

Check the CLI test. From $SPLUNK_HOME/bin Check help for test... ./splunk test help ./splunk test sourcetype

Example:

./splunk test sourcetype /opt/tradelog/trade_entries.log

PROPERTIES OF /opt/log/tradelog/trade_entries.log
Attr:ANNOTATE_PUNCT True
Attr:BREAK_ONLY_BEFORE
Attr:BREAK_ONLY_BEFORE_DATE True
Attr:CHARSET UTF-8
Attr:DATETIME_CONFIG /etc/datetime.xml
Attr:HEADER_MODE
Attr:LEARN_SOURCETYPE true
Attr:LINE_BREAKER_LOOKBEHIND 100
Attr:MAX_DAYS_AGO 2000
Attr:MAX_DAYS_HENCE 2
Attr:MAX_DIFF_SECS_AGO 3600
Attr:MAX_DIFF_SECS_HENCE 604800
Attr:MAX_EVENTS 256
Attr:MAX_TIMESTAMP_LOOKAHEAD 44
Attr:MUST_BREAK_AFTER
Attr:MUST_NOT_BREAK_AFTER
Attr:MUST_NOT_BREAK_BEFORE
Attr:SEGMENTATION indexing
Attr:SEGMENTATION-all full
Attr:SEGMENTATION-inner inner
Attr:SEGMENTATION-outer outer
Attr:SEGMENTATION-raw none
Attr:SEGMENTATION-standard standard
Attr:SHOULD_LINEMERGE False
Attr:TRANSFORMS Attr:TRUNCATE 10000
Attr:is_valid True
Attr:maxDist 100
Attr:sourcetype trade_entries-2

Note attributes including sourcetype.

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...