- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I have the universal forwarder installed on a Windows 2012 server. I am trying to monitor a log directory for a custom application. The application creates a new log file for each month, so I have many text files in the folder that look like 201808.txt, 201807.txt, 201806.txt, etc.
When I monitor the directory, instead of hardcoding the sourcetype that I am telling splunk to do, it is instead setting the sourcetype to the filename. How can I fix this?
On the Windows Server, inputs.conf:
[monitor://C:\BlueIris\log]
disabled = false
sourcetype = blueiris
On the indexer, props.conf:
[blueiris]
sourcetype = blueiris
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I got to the bottom of this.
My original post was actually correct, but I had it in the wrong place, as I was erroneously placing this in $SPLUNK_HOME/etc/apps/SplunkUniversalForwarder/local/inputs.conf when it needed to be in $SPLUNK_HOME/etc/apps/search/inputs.conf. You don't need a props.conf defined on either the Windows host or the main Indexer for this to work.
[monitor://C:\BlueIris\log\]
disabled = false
sourcetype = blueiris
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I got to the bottom of this.
My original post was actually correct, but I had it in the wrong place, as I was erroneously placing this in $SPLUNK_HOME/etc/apps/SplunkUniversalForwarder/local/inputs.conf when it needed to be in $SPLUNK_HOME/etc/apps/search/inputs.conf. You don't need a props.conf defined on either the Windows host or the main Indexer for this to work.
[monitor://C:\BlueIris\log\]
disabled = false
sourcetype = blueiris
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content

The second stanza is redundant. There is no reason to assign sourcetype blueiris
to something that comes in as sourcetype blueiris
.
Also, sourcetype
is not one of the keywords for a monitor
stanza.
Try it without assigning sourcetype
in that first stanza at all...
...and add a props.conf stanza that sets the sourcetype
based on the source
, like this...
[source:://C:\BlueIris\log*]
sourcetype = blueiris
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
No change.
I first removed this from props.conf on the INDEXER:
[blueiris]
sourcetype = blueiris
Then, I changed the inputs.conf on the Windows Unviersal Forwarder to this:
[monitor://C:\BlueIris\log]
disabled = false
And then I added a props.conf file on Windows that shows this:
[source:://C:\BlueIris\log*]
sourcetype = blueiris
But after doing all that, it still is being tagged with the incorrect sourcetype.
