Modify input settings
After you select the source or set your source type when uploading or monitoring a single file, the Modify input settings page appears in .
You can specify additional parameters for your data input, such as its source type, application context, host value, and the index where data from the input is to be stored.
Configure source type
You can specify the source type to be applied to your data with the Source type setting. This setting appears in these situations:
- When you specify a directory as a data source.
- When you specify a network input as a data source.
- When you specify a data source that has been forwarded from another Splunk instance.
If your data source doesn't meet these criteria, then you won't see the Source type setting.
Specify a source type
To specify a source type, select one of these options:
|Click this button to apply the source type that you specify to the data.
|Click this button to add a new source type.
Choose an existing source type
- From the Select Source Type drop-down list, choose the category that best represents the data's source type.
- Choose the source type from the list that appears.
Add a new source type
- In the Source Type text field, enter the name of the new source type.
- Choose a category for the source type in the Source Type Category drop-down list.
- In the Source Type Description text field, enter the description for the source type.
Configure host value
tags events with a host. The default host value is the hostname or IP address of the indexer or forwarder that initially ingests the data. However, you can configure how the software determines the host value. Configure a host value by choosing one of these available host values:
|This value uses the IP address of the host from which the event originates.
|This value uses Domain Name Services (DNS). Events are tagged with the host name that Splunk software determines using DNS name resolution.
|This value uses the host value you assign in the "Host field value" text field that appears when you select this option.
Store an event in an index
The Index setting determines the index where the events for this input are to be stored.
- To use the default index, leave the drop-down list option set to
Default. Otherwise, click the drop-down list and select the index you want the data to go to.
- (Optional) If the index you want to send the data to isn't in the list and you have permissions to create indexes, you can create a new index by clicking the Create a new index button.
- After you make your selections, click Next.
Modify event processing
Distribute source type configurations in Splunk Enterprise
This documentation applies to the following versions of Splunk Cloud Platform™: 9.1.2312, 8.2.2202, 8.2.2112, 8.2.2201, 8.2.2203, 9.0.2205, 9.0.2208, 9.0.2209, 9.0.2303, 9.0.2305 (latest FedRAMP release), 9.1.2308