All Apps and Add-ons

Different sourcetype naming: Splunk 7.2.4 and 8.* or is it the Heavy Forwarder?

afx
Contributor

Hi,
all our UF and HF use the following for the Windows input:

[WinEventLog://Security]
sourcetype=XmlWinEventLog:Security
renderXml=1
...

All UF and the cluster is Splunk 7.2.4.2
I recently installed a few HF and there used the latest Splunk Code: 8.0.2

My 7.* UF arrive with the following source type and source:

XmlWinEventLog:Security  XmlWinEventLog

My 8.* HF arrive instead with:

WinEventLog:Security xmlwineventlog

Any Ideas what's going wrong?

I have the Splunk_TA_windows installed on the Search Head which renames all the source types, but that of course applies to all win source types. But it looks like the source type renaming only applies for the HF and it still does not explain why the source is changed as well.

thx
afx

0 Karma

codebuilder
Influencer

Verify that props.conf on your 8.* HF's is owned by splunk:splunk. Also, any change to props.conf requires cycling the Splunk daemon to take effect.

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

afx
Contributor

My 8.* forwarder runs on Windows as local:system.
There is no props.conf for the windows event log on the box. Just an input like on all other windows boxes.

cheers
afx

0 Karma
Get Updates on the Splunk Community!

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...

Get the T-shirt to Prove You Survived Splunk University Bootcamp

As if Splunk University, in Las Vegas, in-person, with three days of bootcamps and labs weren’t enough, now ...

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...