Hello,
In one of the windows machine logs (path: C:\servicedesk\logs) sending via the universal forwarder to Splunk. So I created inputs.conf and below are the monitor paths, so now am getting logs from sourcetype=%sit% but no logs are coming from sourcetype=automation. Why logs are not coming under sourcetype=automation.
[monitor://C:\servicedesk\logs]
disabled = 0
index = main
sourcetype = %sit%
[monitor://C:\servicedesk\logs]
disabled = 0
index = main
sourcetype = automation
HI,
there is no difference in both stanzas, both are same logs, but here am i created for the first time sourcetype=%sit% am getting logs after i changes to sourcetype=Automation and disabled sourcetype=%sit% am not getting logs, so now i want logs will be index only with sourcetype=Automation.
Hi @phanichintha ,
You definifed the same path in 2 different stanzas.
What is the difference in the events/logs between sourcetypes "%sti%" and "automation"?
BR
Ralph
HI,
there is no difference in both stanzas, both are same logs, but here am i created for the first time sourcetype=%sit% am getting logs after i changes to sourcetype=Automation and disabled sourcetype=%sit% am not getting logs, so now i want logs will be index only with sourcetype=Automation.
HI, after i set for only one stanza i got my results, problem solved.