Getting Data In

Universal forwarder Sourcetype name changes itself

ea7777777
New Member

Hello,

a Universal Forwarder (7.0.1) is watches an textfile. The parameter are following:

[default]
host = RBD9EUFN

[monitor://C:\ProgramData\Cognex\In-Sight\Splunk\Log_Cam]
index = rbg_ff1_stand_allone_ant2
sourcetype = rbg_ff1_stand_allone_ant2_sourcetype

crcSalt = <SOURCE>
followTail = 1 

The strange thing is, the sourcetype name changes itself! Why?

alt text

0 Karma

PavelP
Motivator

Hello @ea7777777 ,

are the log files in this folder being renamed? If yes, do they have the similar suffix (1-2-2-2)?

check on indexer (and on UF too, if you use INDEXED_EXTRACTIONS or local_processing) if there is any sourcetype renaming in any transforms.conf file:

on linux:

grep -Er MetaData:Sourcetype /opt/splunk/etc/*

on Windows:

findstr /s MetaData:Sourcetype c:\ProgramFiles\Splunk\etc\*

or by using btool

splunk btool transforms list --debug |grep MetaData:Sourcetype

splunk btool transforms list --debug |findstr MetaData:Sourcetype
0 Karma

richgalloway
SplunkTrust
SplunkTrust

The host name in your screen shot does not match the host name in your config.

---
If this reply helps you, Karma would be appreciated.

codebuilder
Influencer

Try this instead:

tstats count where index=rbg_ff1_stand_allone_ant2 by sourcetype
----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...