Getting Data In

Using sourcetype in input.conf in Batch mode doesn't appear to work

robsenk
Engager

I noticed that source is not available in the Batch mode unlike the monitor mode. I wonder if the same applies to sourcetypes? It wasn't explicitly mentioned in the docs.

0 Karma
1 Solution

lguinn2
Legend

I have used sourcetype with batch inputs. Here is an example that works

[batch://myinputdirectory]
move_policy = sinkhole
index = xyz
sourcetype = xyz

View solution in original post

robsenk
Engager

I have confirmed this to work in Splunk 5.0.4 build 172409. I will upgrade.

0 Karma

lguinn2
Legend

I have used sourcetype with batch inputs. Here is an example that works

[batch://myinputdirectory]
move_policy = sinkhole
index = xyz
sourcetype = xyz

robsenk
Engager

We upgraded but I believe the fix was from simplifying the transforms.conf. I found I didn't have the exact same environment on my test box. Thanks for you help.

0 Karma

lguinn2
Legend

Worked for me in several versions...

Do you have a typo somewhere? You might want to check everything one more time before you upgrade!

0 Karma

robsenk
Engager

Ok... that's what I have as well. I will go dig further. I should have listed the build we use. version 5.0.3, build 163460. Thanks for comment.

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...