Getting Data In

How to can I configure dynamic sourcetype assignment on a Universal Forwarder or a Heavy Forwarder?

santosh_sshanbh
Path Finder

I have a folder which has multiple log files in format CalculationMgr-xxx(xx).log and EventMgr-xxx(xx).log where xx is a numeric value. I tried configuring 2 separate monitor stanza on UF to monitor these log files but it didn't work. So I have to configure a single stanza as below

# Monitors CalculationMgr & EventMgr Log File
[monitor://D:\Program Files (x86)\LogFiles\]
disabled = false
source = Log
recursive = false
queue = parsingQueue
whitelist = (?i)CalculationMgr-\d+\(\d+\)\.log$|(?i)EventMgr-\d+\(\d+\)\.log$
_TCP_ROUTING = development_hf
followTail = 0
ignoreOlderThan = 10d

Now, I want to set separate source type for these 2 log files. So I tried doing this at both location UF and HF as per below configuration. But getting no success.

On UF

props.conf

[source::.../LogFiles/EventMgr*.log]
sourcetype = EventMgr1

[source::.../LogFiles/CalculationMgr*.log]
sourcetype = CalculationMgr1

On HF

props.conf

[source::Log]
TRANSFORMS-changesourcetype = set_sourcetype_calculationmgr, set_sourcetype_eventmgr

transforms.conf

[set_sourcetype_calculationmgr]
REGEX = (?i)^CalculationMgr\S+
DEST_KEY = MetaData:Sourcetype
FORMAT = sourcetype::CalculationMgr1

[set_sourcetype_eventmgr]
REGEX = (?i)^EventMgr\S+
DEST_KEY = MetaData:Sourcetype
FORMAT = sourcetype::EventMgr1

Any comment on what is wrong in this configuration? How can I achieve the results on Windows platform?

0 Karma

FrankVl
Ultra Champion

Can you share the separate input stanzas you had in your first attempt? Because it should very well be possible to set it up like that, which would make your whole config a lot simpler I guess.

0 Karma

ansif
Motivator

-Try by removing source override @UF inputs.conf.
-Make use of HF to do props.conf and transforms.conf and remove it from UF
- Make necessary changes to your configuration files.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...