Getting Data In

Several small log files - sourcetype = local-too_small

ikulcsar
Communicator

Hi,

I've got a problem with monitoring several log files generated by syslog-ng. There are 50+ switches. I am collecting their logs with a syslog-ng server, generating separate log files for every switch, every day. Some of them send only a few lines so that logs file is small.
I can collect all the logs, but I have got an issue with the sourcetype. All (most?) of the small log file has a local-too_small sourcetype instead of syslog, which I configured explicitly. Based on my research and testing, the auto sourcetype can cause this, but I already add the sourcetype. So what I am doing wrong, why the Splunk ignore it?

inputs.conf:
[monitor:///var/log/remotelogs/*/log/]
host_segment = 8
index = default
sourcetype=syslog

Regards,
István

ikulcsar
Communicator

Hi,

Finally, I reinstall it from the scratch with Splunk Ent. 7.0, reconfigure the inputs and it works... I can not explain and unfortunately cannot reproduce that behavior...

Thank you for your kind help.
Regards,
István

0 Karma

ikulcsar
Communicator

Hi,

Finally, I reinstall it from the scratch with Splunk Ent. 7.0, reconfigure the inputs and it works... I can not explain and unfortunately cannot reproduce that behavior...

Thank you for your kind help.
Regards,
István

0 Karma

harsmarvania57
Ultra Champion

Hi @ikulcsar,

Can you please check your inputs.conf configuration using btool $SPLUNK_HOME/bin/splunk cmd btool inputs --debug list and check whether sourcetype=syslog is assigned to your monitor stanza or not? If it is assigned then can you please try to restart splunkforwarder ?

0 Karma

ikulcsar
Communicator

Hi,
Thank you for your comment. Here is the output. I modified the monitor definition to be more specific, restart the full server, too. But no change.

/opt/splunk/etc/system/local/inputs.conf [monitor:///var/log/remotelogs//log///]
/opt/splunk/etc/system/default/inputs.conf _rcvbuf = 1572864
/opt/splunk/etc/system/local/inputs.conf host = shadow
/opt/splunk/etc/system/local/inputs.conf host_segment = 8
/opt/splunk/etc/system/local/inputs.conf index = default
/opt/splunk/etc/system/local/inputs.conf sourcetype = syslog

Any other idea?

Regards,
István

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...