I'm in the process of migrating one environment's data to its new environment. I have specific hosts forwarding data using the [<host>] stanza in props.conf, but am having problems getting a sourcetype stanza to work.
Working config:
HF sea->atl
props.conf
[host::SEAFwd1]
TRANSFORMS-routing = routeALL, routeTest
TZ = US/Eastern
transforms.conf
[routeALL]
REGEX=(.)
DEST_KEY = _TCP_ROUTING
#FORMAT = Everything
FORMAT = default-autolb-group
[routeTest]
REGEX = .
DEST_KEY = _TCP_ROUTING
FORMAT = Subsidiary,default-autolb-group
outputs.conf
[tcpout]
defaultGroup = default-autolb-group
[tcpout:default-autolb-group]
disabled = false
server = splidx01.local:9997,splidx02.local:9997,splidx03.local:9997,splidx04.local:9997
[tcpout:Subsidiary]
disabled = false
server=newfwd1:9997,newfwd2:9997
I'm attempting to add another source (from another heavy forwarder, no less), with less success. Syslog/cisco hf -> sea hf (splclus1q) -> atl
Syslog/cisco hf
props.conf
[(?::){0}cisco:*]
TRANSFORMS-routing = routeALL, routeTest
TZ = US/Eastern
transforms.conf
[routeALL]
REGEX = (.)
DEST_KEY = _TCP_ROUTING
FORMAT = default-autolb-group
[routeTest]
REGEX = .
DEST_KEY = _TCP_ROUTING
FORMAT = Subsidiary,default-autolb-group
outputs.conf
[tcpout]
defaultGroup = default-autolb-group
[tcpout:default-autolb-group]
disabled = false
server = splidx01.local:9997,splidx02.local:9997,splidx03.local:9997,splidx04.local:9997
[tcpout:Subsidiary]
disabled = false
server = splclus01q.local:9997
New Sea HF props stanza =
[host::\b(SEAFwd1|Syslog/cisco hf)
TRANSFORMS-routing = routeALL, routeTest
TZ = US/Eastern
[(?::){0}cisco:*]
TRANSFORMS-routing = routeALL, routeTest
TZ = US/Eastern
And I'm not seeing the sourcetype in the new environment. Can someone help spot what I'm doing wrong? Thanks.
↧