How can I define a custom source type with in universal forwarder so that it can be seen in splunk indexer?
You will want to set that on the input.
Example:
[monitor:///var/log/syslog]
sourcetype = MY_SOURCETYPE
disabled = false
http://www.splunk.com/base/Documentation/5.0/Admin/Inputsconf
The thing is, I can see the logs under automated sourcetype. I want to get these logs under my sourcetype.
output.conf file has all the necessary contents as I can see logs remotely.
Do you have outputs configured to send the data to the indexer? Also, the file name is inputs.conf
that should go in that folder. make sure you have the s in there.
I have installed windows splunk forwarder.Splunk indexer is on some other machine altogether. Then in \etc\system\local created a file called input.conf. The conetent of the file is :
[monitor://C:\testlogs]
sourcetype = ForwarderSourceType
source = ForwarderSource
disabled = false
Restarted forwarder and splunk indexer. But this entry is not coming in splunk indexer.
What file are you putting that in? Could you post the input configuration please? Thanks!
It does not work. Do I need to check in any other location?