Getting Data In

What should I be sourcetyping /var/log/messages?

daniel333
Builder

All,

On the list of pretrained sourcetypes I see /var/log/messages as linux_messages_syslog (https://docs.splunk.com/Documentation/Splunk/7.0.3/Data/Listofpretrainedsourcetypes) but in Splunk for Nix I see them setting it as syslog.

What is the prefered sourcetype here? I guess I should point out that I am looking for ideal interoperability with Splunk ES and additional apps down the road.

0 Karma

p_gurav
Champion

You can use "linux_messages_syslog" if you are not using nix app.

0 Karma