Getting Data In

Sourcetypes "cross polinating"

brent_weaver
Builder

I am having an issue with Splunk where the sourcetypes are getting mixed up between actualy sources. For example I have a source called caasraw and cf_raw. Events from caasraw get mixed up with cf_raw and vise versa. I am wondering if there is anything in the config that could cause this. I realize that I a REALLY big question but I am wondering if anyone has an initial thoughts.

I should mention that we are going from fluentd to HEC and in fluentd are leveraging the tagging system to pass in splunk metadata, sourcetype, index etc... This my likely be the problem because we are not using the Treasure Data version, instead the open source version.

I am hoping that someone at least has a suggestion on how to initially approach this issue.

Thanks!

Tags (1)
0 Karma

sbbadri
Motivator

I hope below link helps you,

http://docs.splunk.com/Documentation/Splunk/6.6.2/RESTREF/RESTinput# - data/inputs/udp/{name} or data/inputs/udp/

0 Karma

woodcock
Esteemed Legend

Remember btool is your friend.

0 Karma

brent_weaver
Builder

Hey there - I was looking at btool but cannot find the right combo of commands to show me the transforms and props. I have been suspect that the config (somewhere) is causing this. I am concerned that the transforms stanza name is being reused on multiple sourcetypes. What that cause this to happen?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi brent_weaver,
could you share your inputs.conf?
bye.
Giuseppe

0 Karma

brent_weaver
Builder

There is no inputs.conf since this is going through fluentd's syslog input. We use it as a syslog aggregation point.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

REGISTER NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If ...

Observability | Use Synthetic Monitoring for Website Metadata Verification

If you are on Splunk Observability Cloud, you may already have Synthetic Monitoringin your observability ...

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...