Getting Data In

sourcetype gets "-2" added?

mikelanghorst
Motivator

After setting a rather simple props entry for sourcetype [sharepoint] for our log to break events only after datestamp\s and not datestamp* to keep multiple line messages together. I then input a file via oneshot specifying -sourcetype=sharepoint.

Now when looking at the data, I've got data with sourcetype=sharepoint-2.

What's causing this and how can I prevent it?

Tags (1)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

What might the name of your file be? There are some file patterns that Splunk tries to generate a CSV header for. You can see this in the default props.conf if you look for CHECK_FOR_HEADER. You probably want to disable/override this.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

What might the name of your file be? There are some file patterns that Splunk tries to generate a CSV header for. You can see this in the default props.conf if you look for CHECK_FOR_HEADER. You probably want to disable/override this.

Get Updates on the Splunk Community!

Index This | When is October more than just the tenth month?

October 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

What’s New & Next in Splunk SOAR

 Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us for an ...