Getting Data In

Using sourcetype in input.conf in Batch mode doesn't appear to work

robsenk
Engager

I noticed that source is not available in the Batch mode unlike the monitor mode. I wonder if the same applies to sourcetypes? It wasn't explicitly mentioned in the docs.

0 Karma
1 Solution

lguinn2
Legend

I have used sourcetype with batch inputs. Here is an example that works

[batch://myinputdirectory]
move_policy = sinkhole
index = xyz
sourcetype = xyz

View solution in original post

robsenk
Engager

I have confirmed this to work in Splunk 5.0.4 build 172409. I will upgrade.

0 Karma

lguinn2
Legend

I have used sourcetype with batch inputs. Here is an example that works

[batch://myinputdirectory]
move_policy = sinkhole
index = xyz
sourcetype = xyz

robsenk
Engager

We upgraded but I believe the fix was from simplifying the transforms.conf. I found I didn't have the exact same environment on my test box. Thanks for you help.

0 Karma

lguinn2
Legend

Worked for me in several versions...

Do you have a typo somewhere? You might want to check everything one more time before you upgrade!

0 Karma

robsenk
Engager

Ok... that's what I have as well. I will go dig further. I should have listed the build we use. version 5.0.3, build 163460. Thanks for comment.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...