<?xml version="1.0" ?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
	<channel>
		<title>Splunk Base : SplunkGeneral : #4051</title>
		<link>http://www.splunk.com/support/forum:SplunkGeneral/4051</link>
		<description></description>
		<pubDate>Mon, 13 Feb 2012 12:07:16 PST</pubDate>
		<lastBuildDate>Mon, 13 Feb 2012 12:07:16 PST</lastBuildDate>
		<language>en-us</language>
		<copyright>http://creativecommons.org/licenses/by-nc-nd/2.5/</copyright>
		<item>
			<title>Mysterious IIS-2 sourcetype</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4051/14488</link>
			<description>&lt;p&gt;Had similar experience.  I initially set the sourcetype to automatic for my inputs.  The data was then indexed and I ended up with sourcetype iis-2, iis-3.&lt;/p&gt;

&lt;p&gt;So I then modified the inputs.conf file to manually set the sourcetype to iis.  But my indexed data remained with iis-2 and iis-3.&lt;/p&gt;

&lt;p&gt;According to the manual, changing sourcetype affects new data coming in after the config change, and not the indexed data.&lt;/p&gt;

&lt;p&gt;So i then modified props.conf to rename the sourcetype for the already indexed data.&lt;/p&gt;

&lt;p&gt;[iis-2]&lt;br /&gt;
                  rename = iis&lt;/p&gt;

&lt;p&gt;Below is where I found it in the documentation:&lt;/p&gt;

&lt;p&gt;Override automatic source type:&lt;br /&gt;
&lt;a href=&quot;http://www.splunk.com/base/Documentation/latest/Admin/Bypassautomaticsourcetypeassignment&quot;&gt;http://www.splunk.com/base/Documentation/latest/Admin/Bypassautomaticsourcetypeassignment&lt;/a&gt;&lt;/p&gt;

&lt;p&gt;Renaming Source type:&lt;br /&gt;
 &lt;a href=&quot;http://www.splunk.com/base/Documentation/latest/Admin/Renamesourcetypes&quot;&gt;http://www.splunk.com/base/Documentation/latest/Admin/Renamesourcetypes&lt;/a&gt;&lt;/p&gt;

</description>
			<pubDate>Fri, 10 Sep 2010 08:52:57 PDT</pubDate>
			<author>choneycutt</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4051/14488</guid>
		</item>
		<item>
			<title>Mysterious IIS-2 sourcetype</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4051/13992</link>
			<description>&lt;p&gt;Seeing the same issue here. Any way to change the sourcetype of existing data?&lt;/p&gt;

</description>
			<pubDate>Tue, 06 Apr 2010 10:55:55 PDT</pubDate>
			<author>danieljimenez</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4051/13992</guid>
		</item>
		<item>
			<title>Mysterious IIS-2 sourcetype</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4051/13679</link>
			<description>&lt;p&gt;I've got the same problem. Even specifying the sourcetype in inputs.conf doesn't have an effect. As it is I'm working on using the &amp;quot;rename = iis&amp;quot; key/value pair in my props.conf to manually rename the sourcetype, but it would sure be nice if this worked out of the box.&lt;/p&gt;

</description>
			<pubDate>Tue, 16 Mar 2010 13:54:11 PDT</pubDate>
			<author>bnwri</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4051/13679</guid>
		</item>
		<item>
			<title>Mysterious IIS-2 sourcetype</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4051/13339</link>
			<description>&lt;p&gt;I do have it in inputs.conf:&lt;/p&gt;

&lt;p&gt;[monitor://\\iis_server\&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/LogFiles&quot;&gt;LogFiles&lt;/a&gt;\&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/W3SVC1&quot;&gt;W3SVC1&lt;/a&gt;]&lt;br /&gt;
disabled = 0&lt;br /&gt;
host = iis_server&lt;br /&gt;
sourcetype = IIS&lt;/p&gt;

&lt;p&gt;And it worked fine until 4.0.9.&lt;/p&gt;

</description>
			<pubDate>Thu, 25 Feb 2010 13:27:59 PST</pubDate>
			<author>msallman</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4051/13339</guid>
		</item>
		<item>
			<title>Mysterious IIS-2 sourcetype</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4051/13298</link>
			<description>&lt;p&gt;Agree, there are some opportunities for improvement with the automatic sourcetyper.  The best practice is to manually set the sourcetype in inputs.conf whenever possible.&lt;/p&gt;

</description>
			<pubDate>Wed, 24 Feb 2010 09:38:05 PST</pubDate>
			<author>araitz</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4051/13298</guid>
		</item>
		<item>
			<title>Mysterious IIS-2 sourcetype</title>
			<link>http://www.splunk.com/support/forum:SplunkGeneral/4051/13288</link>
			<description>&lt;p&gt;Since upgrading to 4.0.9, Splunk seems to have decided that I need an IIS-2 sourcetype (created in /etc/apps/learned/local/props.conf as best I can tell).&lt;br /&gt;
Is there a way to get rid of this? I tried deleting the stanza from props.conf (and an apparently associated one in transforms.conf), but Splunk keeps re-creating it/them.&lt;br /&gt;
I already have an IIS sourcetype, so when Splunk decides to use IIS-2 instead, it messes up my searches/reports.&lt;/p&gt;

&lt;p&gt;Thanks&lt;/p&gt;

</description>
			<pubDate>Wed, 24 Feb 2010 06:14:41 PST</pubDate>
			<author>msallman</author>
			<guid>http://www.splunk.com/support/forum:SplunkGeneral/4051/13288</guid>
		</item>
	</channel>
</rss>

