Getting Data In

How do I test sourcetyping before I index

rroberts
Splunk Employee
Splunk Employee

How can I see how Splunk is going to handle a particular dataset BEFORE I actually input? For example: If I monitor a log what sourcetype is splunk going to tag the events with?

Tags (2)
0 Karma
1 Solution

rroberts
Splunk Employee
Splunk Employee

Check the CLI test. From $SPLUNK_HOME/bin Check help for test... ./splunk test help ./splunk test sourcetype

Example:

./splunk test sourcetype /opt/tradelog/trade_entries.log

PROPERTIES OF /opt/log/tradelog/trade_entries.log
Attr:ANNOTATE_PUNCT True
Attr:BREAK_ONLY_BEFORE
Attr:BREAK_ONLY_BEFORE_DATE True
Attr:CHARSET UTF-8
Attr:DATETIME_CONFIG /etc/datetime.xml
Attr:HEADER_MODE
Attr:LEARN_SOURCETYPE true
Attr:LINE_BREAKER_LOOKBEHIND 100
Attr:MAX_DAYS_AGO 2000
Attr:MAX_DAYS_HENCE 2
Attr:MAX_DIFF_SECS_AGO 3600
Attr:MAX_DIFF_SECS_HENCE 604800
Attr:MAX_EVENTS 256
Attr:MAX_TIMESTAMP_LOOKAHEAD 44
Attr:MUST_BREAK_AFTER
Attr:MUST_NOT_BREAK_AFTER
Attr:MUST_NOT_BREAK_BEFORE
Attr:SEGMENTATION indexing
Attr:SEGMENTATION-all full
Attr:SEGMENTATION-inner inner
Attr:SEGMENTATION-outer outer
Attr:SEGMENTATION-raw none
Attr:SEGMENTATION-standard standard
Attr:SHOULD_LINEMERGE False
Attr:TRANSFORMS Attr:TRUNCATE 10000
Attr:is_valid True
Attr:maxDist 100
Attr:sourcetype trade_entries-2

Note attributes including sourcetype.

View solution in original post

0 Karma

rroberts
Splunk Employee
Splunk Employee

Check the CLI test. From $SPLUNK_HOME/bin Check help for test... ./splunk test help ./splunk test sourcetype

Example:

./splunk test sourcetype /opt/tradelog/trade_entries.log

PROPERTIES OF /opt/log/tradelog/trade_entries.log
Attr:ANNOTATE_PUNCT True
Attr:BREAK_ONLY_BEFORE
Attr:BREAK_ONLY_BEFORE_DATE True
Attr:CHARSET UTF-8
Attr:DATETIME_CONFIG /etc/datetime.xml
Attr:HEADER_MODE
Attr:LEARN_SOURCETYPE true
Attr:LINE_BREAKER_LOOKBEHIND 100
Attr:MAX_DAYS_AGO 2000
Attr:MAX_DAYS_HENCE 2
Attr:MAX_DIFF_SECS_AGO 3600
Attr:MAX_DIFF_SECS_HENCE 604800
Attr:MAX_EVENTS 256
Attr:MAX_TIMESTAMP_LOOKAHEAD 44
Attr:MUST_BREAK_AFTER
Attr:MUST_NOT_BREAK_AFTER
Attr:MUST_NOT_BREAK_BEFORE
Attr:SEGMENTATION indexing
Attr:SEGMENTATION-all full
Attr:SEGMENTATION-inner inner
Attr:SEGMENTATION-outer outer
Attr:SEGMENTATION-raw none
Attr:SEGMENTATION-standard standard
Attr:SHOULD_LINEMERGE False
Attr:TRANSFORMS Attr:TRUNCATE 10000
Attr:is_valid True
Attr:maxDist 100
Attr:sourcetype trade_entries-2

Note attributes including sourcetype.

0 Karma
Get Updates on the Splunk Community!

Index This | I’m short for "configuration file.” What am I?

May 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with a Special ...

New Articles from Academic Learning Partners, Help Expand Lantern’s Use Case Library, ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...