Recognize Source Types
This documentation does not apply to the most recent version of Splunk. Click here for the latest version.
Recognize Source Types
Create new source types to describe your data input sources.
Filename
- props.conf (within any subdirectory of $SPLUNK_HOME/etc/bundles/)
Format
[source::<path>] sourcetype=mySourceType ...
Create a new configuration with the path to your file (or files) and the name you wish to assign as a sourcetype.
Examples
[source::/var/log/netinfo.log] sourcetype=netinfo_log
[source::/var/log/httpd/mywebsite_*_log] sourcetype=mywebsite_log
This documentation applies to the following versions of Splunk: 3.2 , 3.2.1 , 3.2.2 , 3.2.3 , 3.2.4 , 3.2.5 , 3.2.6 View the Article History for its revisions.