Getting Data In

Sourcefile name changes at index time - intermittently

timrich66
Communicator

Hi All,

I am currently ingesting plain text files with a filename format as follows - 

4d618da0-48f0-430d-9c9f-10c6e5ba6971_Batch1_20200810.5415.finish

Each day a new files are created with the day's date and a sequential number before the .finish

e.g. 4d618da0-48f0-430d-9c9f-10c6e5ba6971_Batch1_yyyymmdd.nnnn.finish

 

When the files are ingested, the source name extension is (intermittently) changed from ending 'nnnn.finsh' to '.xml'

e.g. 4d618da0-48f0-430d-9c9f-10c6e5ba6971_Batch1_20200810.xml

We are running a distributed environment with 4 indexers.  This trait is being seen across all indexers and on files being ingested from different servers.  

As I rely on checking for '.finish' in the source, is there a way of setting props or transforms to stop the file extension being changed?

I hope this makes some sense.  Thanks in advance for assistance.

 

 

 

Labels (3)
0 Karma
1 Solution

timrich66
Communicator

I appear to have fixed this.

I have changed the monitor path to read "*.*.finish" and the source name has remained unchanged since.

View solution in original post

0 Karma

timrich66
Communicator

I appear to have fixed this.

I have changed the monitor path to read "*.*.finish" and the source name has remained unchanged since.

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security: Your Command Center for PCI DSS Compliance

Every security professional knows the drill. The PCI DSS audit is approaching, and suddenly everyone's asking ...

Developer Spotlight with Guilhem Marchand

From Splunk Engineer to Founder: The Journey Behind TrackMe    After spending over 12 years working full time ...

Cisco Catalyst Center Meets Splunk ITSI: From 'Payments Are Down' to Root Cause in ...

The Problem: When Networks and Services Don't Talk Payment systems fail at a retail location. Customers are ...