Getting Data In

how to get fifo to be sourceType=syslog?

bbear
Explorer

Greetings experts,

I am using syslog-ng and Splunk on the same box. I have configure syslog-ng to pipe the incoming syslogs to a FIFO and get Splunk to read the FIFO.

Splunk can read and index the FIFO fine but the sourceType is unkown and I am trying to get Splunk to recognize the data as sourceType syslog.

Can this be done? What needs to be modified?

I have tried to configure the /$SPLUNK_HOME/etc/modules/input/FIFO/config.xml file but this did not seem to get the sourceType changed.

Any help would be greatly appreciated.

Bear

Tags (1)

Lowell
Super Champion

A couple of things to point out. (This may vary slightly based on splunk version)

I don't think you should ever have to mess with the etc/modules/... folder so I would recommend undoing any changes you made there.

To set the sourcetype, you should be able to simply set the "sourcetype" parameter in your input stanza. So your inputs.conf entry should look something like this:

[fifo:///var/path/to/fifo]
sourcetype = syslog

I should point out that splunk does not recommend the usage of fifo anymore. So I would suggest either (1) use syslog-ng to write to files and have splunk pick up those files, this has the advantage of protecting you against losing events whenever splunkd is restarted, or (2) if short outages (due to restarts) are not a problem for you then you can configure splunk to listen on a TCP (or UDP) port and have syslog-ng forward your events to that port. (You would use the same sourcetype=syslog option for that input as well.)

bbear
Explorer

Thanks for the help and advice.
I am experimenting with what is easiest and best so I removed the FIFO and went back to reading the udp port.

0 Karma

bbear
Explorer

OK, I figured it out.

I needed to add the sourcetype = syslog to my inputs.conf file under the fifo config.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...