Getting Data In

Monitoring same logs for two different sourcetype

AKG1_old1
Builder

Hello,

we are monitoring GC logs and logs could be in two different format.(Conventional GC and G1)
Requirement is that if logs are in GC format it goes to GC sourcetype and if G1 then G1 sourcetype.

One apporach is to upload these logs twice by setting up 2 different forwarders. but looking for some better approach.

GC logs are complex so redirecting the logs by identifying the type would be difficult.(using props and transform)

Thanks

0 Karma

lakshman239
Influencer

Would it be possible to add a change in the logging application to write the logs to 2 diff files [ one for GC and another for G1]?

If both the events can go to the same sourcetype [ assuming line breaking etc.. is possible], you could we tag them (using eventtypes/tags.conf) to help with your search? would that help?

0 Karma

AKG1_old1
Builder

@lakshman239 : Thanks for reply. No we don't have control over logs so can't add anything to distinguish between sourcetype. Both sourcetype having different linebreaking approach, can go under the same sourcetype.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...