Getting Data In

sourcetype not getting set

bmayer00
Engager

I have the following confs

inputs:

[monitor:///opt/logs/\*.prd/\*/\*EndAudit.csv]
disable = false
index = foo

props:

[source::/opt/logs/\*bfc.sv.prd/\*/HttpConnectorService-\*-FrontEndAudit.csv]
sourcetype = HttpConFramework-FrontEnd-BFC
priority = 101

[source::/opt/logs/\*bfc.sv.prd/\*/HttpConnectorService-\*-BackEndAudit.csv]
sourcetype = HttpConFramework-BackEnd-BFC
priority = 101

these 2 sources are not getting their sourcetype set properly as defined above in the props

if I run ./splunk test sourcetype /opt/logs/symbfc.sv.prd/symbfc111/HttpConnectorService-11.02-FrontEndAudit.csv

Using logging configuration at /opt/instance/splunk/etc/log-cmdline.cfg.
PROPERTIES OF /opt/logs/symbfc.sv.prd/symbfc111/HttpConnectorService-11.02-FrontEndAudit.csv
    <snip>
    Attr:sourcetype HttpConFramework-FrontEnd-BFC
    </snip>

however running:

./splunk test sourcetype /opt/logs/\*bfc.sv.prd/\*/HttpConnectorService-\*-FrontEndAudit.csv

Command error: The argument '/opt/logs/symbfc.sv.prd/symbfc111/HttpConnectorService-11.02-FrontEndAudit.csv' is invalid.  Arguments must be specified in the form '-argument value'.
Tags (1)
0 Karma

hazekamp
Builder

Are there actually wildcard's in your file names? If not you probably don't wan't a string literal wildcard
\*

## inputs.conf
## The ellipsis (...) wildcard recurses through directories and any 
## number of levels of subdirectories to find matches.  
## The asterisk wildcard matches anything in that specific directory path segment.
[monitor:///opt/logs/*.prd/.../*EndAudit.csv]
disable = false
index = foo

## props.conf
[source::/opt/logs/*.prd/.../*FrontEndAudit.csv]
sourcetype = HttpConFramework-FrontEnd-BFC
priority = 101

[source::/opt/logs/*.prd/.../*BackEndAudit.csv]
sourcetype = HttpConFramework-BackEnd-BFC
priority = 101
Get Updates on the Splunk Community!

Splunk Observability Cloud’s AI Assistant in Action Series: Analyzing and ...

This is the second post in our Splunk Observability Cloud’s AI Assistant in Action series, in which we look at ...

Elevate Your Organization with Splunk’s Next Platform Evolution

 Thursday, July 10, 2025  |  11AM PDT / 2PM EDT Whether you're managing complex deployments or looking to ...

Splunk Answers Content Calendar, June Edition

Get ready for this week’s post dedicated to Splunk Dashboards! We're celebrating the power of community by ...