Getting Data In

sourcetype Help !!

rakesh_498115
Motivator

Hi

I Have installed splunk forwarders in 4 servers and search head in 1 server .Now in all the splunk forwarders i have configured the inputs.conf file..with the index details and the input details..

configurations in inputs.conf file ::

[folder path]
sourcetype=A
index=A

and in search head i have configured the props.conf file...and restrated all the splunk servers....

configurations in prop file

[A]
linebreaker=/L:RECORD

Now i have opened the searched and tried to use the general search query..whether my sourcetypes are created or not..

like this ..

sourcetype="A" . but this is not working..

but when i give with the index name created for that sourcetype as ..

index="A" its working....

How can i make the sourcetype to work in the search head..do i have to do any changes in the inputs.conf file of the search head...Please help asap..

Tags (1)
0 Karma
1 Solution

lguinn2
Legend

When you create a new index, it is usually not searched automatically - depending on how roles are set up. Go to Manager->Access Controls->Roles. Check each role that should have access to index A. Does the role have access? Does it search index A by default?

If a role does not search index A by default (as yours probably does not), you must specify the index when you search. That's why index=A works, and sourcetype=A does not.

View solution in original post

lguinn2
Legend

When you create a new index, it is usually not searched automatically - depending on how roles are set up. Go to Manager->Access Controls->Roles. Check each role that should have access to index A. Does the role have access? Does it search index A by default?

If a role does not search index A by default (as yours probably does not), you must specify the index when you search. That's why index=A works, and sourcetype=A does not.

jbsplunk
Splunk Employee
Splunk Employee

Good thinking...along those lines search liked 'index=A sourcetype=A' would also return results.

0 Karma

jbsplunk
Splunk Employee
Splunk Employee

what is the sourcetype of the event when you search in index A? Inputs.conf is where the sourcetype should be defined, and if you've defined it as specified above, that should be sufficient.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...