All Apps and Add-ons

Apply sourcetype on FTP Input (FTP Pull App)

pgylbert
New Member

I have a production equipment storing a log that I can access through FTP. I installed FTP Pull and set up an input and it works OK that far. However, the file format is a bit odd, so simply taking it in is not enough. (It has a special timestamp that Splunk does not interpret correctly out of the box, and there is no header line in the file). I have created a new sourcetype where I configured timestamp format and field names. When I upload the file manually and apply that particular sourcetype, data is indexed properly. I selected this sourcetype in the FTP Input configuration but it does not seem to take effect. The indexed events get this selected sourcetype associated, but the configuration of the sourcetype is not observed, so when the file comes through FTP, it is indexed incorrectly.

Is there a way to enforce the FTP Input to actually apply the configuration of the selected sourcetype?

Thanks in advance for sharing your thoughts or experience with me

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...