Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

How do I configure custom sourcetypes on Universal Forwarders and Indexers?

$
0
0
I have two Linux VMs set up, one with a Universal Forwarder and one with an Indexer. I have a script that generates dummy data (on the forwarder) that needs a custom sourcetype set up in order to parse the events correctly. On the Universal Forwarder props.conf is currently empty, and inputs.conf contains: [monitor:///home/splunk/data/data1*.soap] _TCP_ROUTING = SOAP disabled = false sourcetype = soaptype On the Indexer, props.conf contains: [soaptype] BREAK_ONLY_BEFORE = As of right now my events aren't making it into the indexer at all. If I remove the sourcetype from inputs.conf and props.conf, data appears, but it is splitting the events incorrectly. Any suggestions? Many thanks!

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>