Getting Data In
Highlighted

Using sourcetype in input.conf in Batch mode doesn't appear to work

Engager

I noticed that source is not available in the Batch mode unlike the monitor mode. I wonder if the same applies to sourcetypes? It wasn't explicitly mentioned in the docs.

0 Karma
Highlighted

Re: Using sourcetype in input.conf in Batch mode doesn't appear to work

Legend

I have used sourcetype with batch inputs. Here is an example that works

[batch://myinputdirectory]
move_policy = sinkhole
index = xyz
sourcetype = xyz

View solution in original post

Highlighted

Re: Using sourcetype in input.conf in Batch mode doesn't appear to work

Engager

Ok... that's what I have as well. I will go dig further. I should have listed the build we use. version 5.0.3, build 163460. Thanks for comment.

0 Karma
Highlighted

Re: Using sourcetype in input.conf in Batch mode doesn't appear to work

Legend

Worked for me in several versions...

Do you have a typo somewhere? You might want to check everything one more time before you upgrade!

0 Karma
Highlighted

Re: Using sourcetype in input.conf in Batch mode doesn't appear to work

Engager

We upgraded but I believe the fix was from simplifying the transforms.conf. I found I didn't have the exact same environment on my test box. Thanks for you help.

0 Karma
Highlighted

Re: Using sourcetype in input.conf in Batch mode doesn't appear to work

Engager

I have confirmed this to work in Splunk 5.0.4 build 172409. I will upgrade.

0 Karma