Getting Data In

how to get fifo to be sourceType=syslog?

bbear
Explorer

Greetings experts,

I am using syslog-ng and Splunk on the same box. I have configure syslog-ng to pipe the incoming syslogs to a FIFO and get Splunk to read the FIFO.

Splunk can read and index the FIFO fine but the sourceType is unkown and I am trying to get Splunk to recognize the data as sourceType syslog.

Can this be done? What needs to be modified?

I have tried to configure the /$SPLUNK_HOME/etc/modules/input/FIFO/config.xml file but this did not seem to get the sourceType changed.

Any help would be greatly appreciated.

Bear

Tags (1)

Lowell
Super Champion

A couple of things to point out. (This may vary slightly based on splunk version)

I don't think you should ever have to mess with the etc/modules/... folder so I would recommend undoing any changes you made there.

To set the sourcetype, you should be able to simply set the "sourcetype" parameter in your input stanza. So your inputs.conf entry should look something like this:

[fifo:///var/path/to/fifo]
sourcetype = syslog

I should point out that splunk does not recommend the usage of fifo anymore. So I would suggest either (1) use syslog-ng to write to files and have splunk pick up those files, this has the advantage of protecting you against losing events whenever splunkd is restarted, or (2) if short outages (due to restarts) are not a problem for you then you can configure splunk to listen on a TCP (or UDP) port and have syslog-ng forward your events to that port. (You would use the same sourcetype=syslog option for that input as well.)

bbear
Explorer

Thanks for the help and advice.
I am experimenting with what is easiest and best so I removed the FIFO and went back to reading the udp port.

0 Karma

bbear
Explorer

OK, I figured it out.

I needed to add the sourcetype = syslog to my inputs.conf file under the fifo config.

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...