Getting Data In

sourcetype from universal forwarder to splunk indexer

yuriy_zubarev
Engager

The universal forwarder has a very simple configuration of what to scan for (inputs.conf) and where to send it to (outputs.conf).

Splunk indexer has the following in props.conf

[source::.../....log4j]
sourcetype = log4j

I want every *.log4j file to have "log4j" sourcetype but it doesn't work when receiving information from the forwarder.

For example, I see the following from "summary" screen in indexer:

source: /data1/packages/apache-tomcat/logs/splunk/splunk-test/app.log.2011-04-04.log4j
sourcetype: app.log

How can I have "app.log.2011-04-04.log4j" to be assigned "log4j" sourcetype?

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

You need to put that [source::.../....log4j] stanza on the forwarder, where it will be set on the input. Please see: http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F

View solution in original post

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

You need to put that [source::.../....log4j] stanza on the forwarder, where it will be set on the input. Please see: http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

.conf25 Global Broadcast: Don’t Miss a Moment

Hello Splunkers, .conf25 is only a click away.  Not able to make it to .conf25 in person? No worries, you can ...

Observe and Secure All Apps with Splunk

 Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What's New in Splunk Observability - August 2025

What's New We are excited to announce the latest enhancements to Splunk Observability Cloud as well as what is ...