Hello,
a Universal Forwarder (7.0.1) is watches an textfile. The parameter are following:
[default]
host = RBD9EUFN
[monitor://C:\ProgramData\Cognex\In-Sight\Splunk\Log_Cam]
index = rbg_ff1_stand_allone_ant2
sourcetype = rbg_ff1_stand_allone_ant2_sourcetype
crcSalt = <SOURCE>
followTail = 1
The strange thing is, the sourcetype name changes itself! Why?
Hello @ea7777777 ,
are the log files in this folder being renamed? If yes, do they have the similar suffix (1-2-2-2)?
check on indexer (and on UF too, if you use INDEXED_EXTRACTIONS or local_processing) if there is any sourcetype renaming in any transforms.conf file:
on linux:
grep -Er MetaData:Sourcetype /opt/splunk/etc/*
on Windows:
findstr /s MetaData:Sourcetype c:\ProgramFiles\Splunk\etc\*
or by using btool
splunk btool transforms list --debug |grep MetaData:Sourcetype
splunk btool transforms list --debug |findstr MetaData:Sourcetype
The host name in your screen shot does not match the host name in your config.
Try this instead:
tstats count where index=rbg_ff1_stand_allone_ant2 by sourcetype