Hi,
i'd install the "Security Intelligence for Vormetric Data Firewall (TM)" app to our running splunk system and I want to use the predefined tcp://5524 source.
inputs.conf
[tcp://5514]
disabled = false
index = myindex
connection_host = dns
sourcetype = rfc5424_syslog
If i now try to search the sourcetype "rfc5424_syslog" i have no results.
The search about the "source=tcp:5541" shows for the vormetric data the sourcetype "syslog".
Overwrites splunk the sourcetype? Why is it syslog not rfc5424_syslog? In the inputs.conf the sourcetype is correct. Because this issue the Vormetric app doesn't work.
I hope anybody have an idea. Thanks in advance.
Regards Arne
The Vormetric app includes the definitions for rfc5424_syslog so no other apps are required.
There is a test for valid rfc5424 format in the default/transforms.conf installed with the app, which looks like this:
[test_for_syslog]
REGEX = ^<\d+>[^1]
FORMAT = sourcetype::syslog
DEST_KEY = MetaData:Sourcetype
http://tools.ietf.org/html/rfc5424
If the header doesn't match, this rule changes the format back to plain syslog, which may be what you are seeing.
How did you genenerate the RFC5424 format? Have you selected it in the server or agent log setup?
What other apps have you installed? For example, have you installed the 'rfc5424' app? I suspect that other inputs and/or props entries are conflicting with what you created. You can use btool (http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Usebtooltotroubleshootconfigurati...) to determine where the various properties are coming from, using something like this:
splunk cmd btool props list --debug | more
(and then look for the stanzas containing 5541, and the associated properties). The Splunk on Splunk (SoS) app has a prettier UI for investigating these sorts of configuration issues.
Try changing the sourcetype in props.conf:
e.g. This stanza:
source::tcp:5541
sourcetype = rfc5424_syslog
http://answers.splunk.com/answers/39176/change-the-syslog-sourcetype
ty for help but it doesn't work
i'd try
[source::tcp:5541]
sourcetype = rfc5424_syslog
and
[source::host:xx.xxx.xx.xxx}
sourcetype = rfc5424_syslog
as well... but no change happend... 😕
which props.conf should i use... the app props.conf or system/local/props.conf ?