source type

noun

A default field that identifies the source type of the event -- the data format type from which the event originates, such as access_combined or cisco_syslog.

Splunk comes with a large set of predefined source types, and will assign a source type automatically to your data. A Splunk administrator can also override what Splunk chooses, or add to the set of source types to support custom data types.

The indexer identifies and adds the source type field at when the data is indexed. As a result, each event in Splunk has a sourcetype field.

Use the sourcetype field in searches to make it easy to find all data of a certain type (as opposed to all data from a single source).

For more information

In the Getting Data In Manual:

configuration

configuration file

event processing

character set encoding

segmentation

segment

timestamping

timestamp, timezone offset

default field extraction

host, source, source type, punct


archiving

retention time