Getting Data In

sourcetype gets "-2" added?

mikelanghorst
Motivator

After setting a rather simple props entry for sourcetype [sharepoint] for our log to break events only after datestamp\s and not datestamp* to keep multiple line messages together. I then input a file via oneshot specifying -sourcetype=sharepoint.

Now when looking at the data, I've got data with sourcetype=sharepoint-2.

What's causing this and how can I prevent it?

Tags (1)
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

What might the name of your file be? There are some file patterns that Splunk tries to generate a CSV header for. You can see this in the default props.conf if you look for CHECK_FOR_HEADER. You probably want to disable/override this.

View solution in original post

gkanapathy
Splunk Employee
Splunk Employee

What might the name of your file be? There are some file patterns that Splunk tries to generate a CSV header for. You can see this in the default props.conf if you look for CHECK_FOR_HEADER. You probably want to disable/override this.

Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...