Getting Data In

What should I be sourcetyping /var/log/messages?

daniel333
Builder

All,

On the list of pretrained sourcetypes I see /var/log/messages as linux_messages_syslog (https://docs.splunk.com/Documentation/Splunk/7.0.3/Data/Listofpretrainedsourcetypes) but in Splunk for Nix I see them setting it as syslog.

What is the prefered sourcetype here? I guess I should point out that I am looking for ideal interoperability with Splunk ES and additional apps down the road.

0 Karma

p_gurav
Champion

You can use "linux_messages_syslog" if you are not using nix app.

0 Karma
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...