Greetings all,
We just upgraded from 4.0.3 to 4.3.1 and are having a few issues with what seems like local config files not working the same as they used to.
The first problem is with props and transforms. Here is a sample message we might see in our splunk from our .net application:
Apr 20 17:09:41 10.1.1.10 /LM/W3SVC/1831898534/ROOT-1-129793713578578256: 2012-04-20 17:26:47,779
Type= ERROR
Module= Toolbox.ContentPieces.GroupMessage
PrettyUrl= /trd/9/2/4746490/1/viewonline
Referrer=
RawURL= http://it.toolbox.com/r/trd.aspx?pid=9&tid=2&item=4746490&ctid=1&subtype=viewonline&
UserAgent= Mozilla/5.0 (X11; U; Linux x86_64; en-US) AppleWebKit/532.9 (KHTML, like Gecko) Chrome/5.0.307.11 Safari/532.9
Message= Unable to get Content Activity records
Contribid=0 LocalID=4746489 type=1
A section of my transforms.conf in etc/system/local/:
[Type_for_sourcetype_syslog_1]
REGEX = Type=(.*?)\n
FORMAT = Type::$1
[Module_for_sourcetype_syslog_1]
REGEX = Module=(.*?)\n
FORMAT = Module::$1
A section from my props.conf in etc/system/local/:
[syslog]
REPORT-Type_for_sourcetype_syslog_1 = Type_for_sourcetype_syslog_1
REPORT-Message_for_sourcetype_syslog_1 = Message_for_sourcetype_syslog_1
Previously this worked, and we would have fields that would show up for Type and Message (among all the others, just giving brief examples) on the left hand side. They still show up as "interesting fields" and fields that are indexed, but they aren't there as default. Secondly in my props.conf is the following:
[syslog]
SHOULD_LINEMERGE=true
BREAK_ONLY_BEFORE_DATE=true
LINE_BREAKER=([\r\n]+)
I'm just posting snippets, this is in the same [syslog] section that was used to define the sourcetypes up above. Now I know SOME of the local configs, because this:
imputs.conf in etc/system/local:
[udp://6164]
disabled = false
sourcetype = syslog
Is working an expected. Any help? Any more info you guys need?
... View more