Getting Data In

Several small log files - sourcetype = local-too_small

ikulcsar
Communicator

Hi,

I've got a problem with monitoring several log files generated by syslog-ng. There are 50+ switches. I am collecting their logs with a syslog-ng server, generating separate log files for every switch, every day. Some of them send only a few lines so that logs file is small.
I can collect all the logs, but I have got an issue with the sourcetype. All (most?) of the small log file has a local-too_small sourcetype instead of syslog, which I configured explicitly. Based on my research and testing, the auto sourcetype can cause this, but I already add the sourcetype. So what I am doing wrong, why the Splunk ignore it?

inputs.conf:
[monitor:///var/log/remotelogs/*/log/]
host_segment = 8
index = default
sourcetype=syslog

Regards,
István

ikulcsar
Communicator

Hi,

Finally, I reinstall it from the scratch with Splunk Ent. 7.0, reconfigure the inputs and it works... I can not explain and unfortunately cannot reproduce that behavior...

Thank you for your kind help.
Regards,
István

0 Karma

ikulcsar
Communicator

Hi,

Finally, I reinstall it from the scratch with Splunk Ent. 7.0, reconfigure the inputs and it works... I can not explain and unfortunately cannot reproduce that behavior...

Thank you for your kind help.
Regards,
István

0 Karma

harsmarvania57
Ultra Champion

Hi @ikulcsar,

Can you please check your inputs.conf configuration using btool $SPLUNK_HOME/bin/splunk cmd btool inputs --debug list and check whether sourcetype=syslog is assigned to your monitor stanza or not? If it is assigned then can you please try to restart splunkforwarder ?

0 Karma

ikulcsar
Communicator

Hi,
Thank you for your comment. Here is the output. I modified the monitor definition to be more specific, restart the full server, too. But no change.

/opt/splunk/etc/system/local/inputs.conf [monitor:///var/log/remotelogs//log///]
/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864
/opt/splunk/etc/system/local/inputs.conf host = shadow
/opt/splunk/etc/system/local/inputs.conf host_segment = 8
/opt/splunk/etc/system/local/inputs.conf index = default
/opt/splunk/etc/system/local/inputs.conf sourcetype = syslog

Any other idea?

Regards,
István

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...