- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Renaming an upgraded event source
This is probably an easy one.
One of my event sources has been upgraded,and renamed by the new vendor. I've been told by the vendor that it logs exactly the same as before the upgrade, and only the name is different. It's collected by File Reader service.
In my test ES, I've tried copying and renaming the previous etc/devices files, and giving it a different device ID in the .ini file. But, when I inject the new raw logs into the ftp_files folder, they're always discovered as unknown.
I'm sure there's a wiki on what to do in this situation, but I can't find it.
Thanks in advance,
--== John
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
I would start by using the event analyzer in the ESI tool to verify that the logs truly have not changed.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
Have you tried just allowing the device to be collected the same way that it was...that is no changes to the name of the device file or anything?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Email to a Friend
- Report Inappropriate Content
