Splunk Search

Splunk for Unix Sourcetypes for syslog

daniel333
Builder

All,

I am looking at Splunk for Unix TA. I see the /var/log/messages input and for the life of me I can't find in this app where it's getting it's sourcetype of "syslog". Skimmed props.conf on the TA (why does the TA have a props?) and the splunk_for_unix_app too.

[monitor:///var/log]
whitelist=(\.log|log$|messages|secure|auth|mesg$|cron$|acpid$|\.out)
blacklist=(lastlog|anaconda\.syslog)
index=os
disabled = 1
0 Karma

ddrillic
Ultra Champion

syslog belongs to a set of predefined source types - What are the default sourcetypes and how are they determined?

The "official" documentation about them at Why source types matter

inventsekar
SplunkTrust
SplunkTrust

Hi Daniel,
This page is listing all the source types from Splunk App for Unix -
http://docs.splunk.com/Documentation/UnixAddOn/5.2.3/User/SourcetypesandCIMdatamodelinfo

why does the TA have a props?
Splunk has config files for separately for "global and app/user contexts", so that maintenance would become easy and simple.
when the number of users and apps grow, these global and app/user contexts help in administration duties.

0 Karma
Get Updates on the Splunk Community!

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...

Combine Multiline Logs into a Single Event with SOCK: a Step-by-Step Guide for ...

Combine multiline logs into a single event with SOCK - a step-by-step guide for newbies Olga Malita The ...