<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: I want source type separation using prop.conf. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/I-want-source-type-separation-using-prop-conf/m-p/579372#M102286</link>
    <description>&lt;P&gt;I want to separate data whenever it comes in. Can similar effects be achieved using prop.conf or transaction.conf?&lt;/P&gt;</description>
    <pubDate>Tue, 28 Dec 2021 11:16:07 GMT</pubDate>
    <dc:creator>noott211</dc:creator>
    <dc:date>2021-12-28T11:16:07Z</dc:date>
    <item>
      <title>I want source type separation using prop.conf.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-want-source-type-separation-using-prop-conf/m-p/579354#M102282</link>
      <description>&lt;P&gt;index name = my_index&lt;BR /&gt;source name = my_source&lt;BR /&gt;sourcetype = my_sourcetpye&lt;BR /&gt;host = 192.168.0.10&lt;/P&gt;&lt;P&gt;-----------------------------&lt;BR /&gt;The field action is =allow -&amp;gt; my_allow.&lt;BR /&gt;Action = deny -&amp;gt; my_deny&lt;BR /&gt;other -&amp;gt; my_myontype&lt;BR /&gt;I want to change it to this.&lt;BR /&gt;&lt;BR /&gt;help me&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 06:34:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-want-source-type-separation-using-prop-conf/m-p/579354#M102282</guid>
      <dc:creator>noott211</dc:creator>
      <dc:date>2021-12-28T06:34:54Z</dc:date>
    </item>
    <item>
      <title>Re: I want source type separation using prop.conf.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-want-source-type-separation-using-prop-conf/m-p/579362#M102285</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;In splunk concept sourcetype means lexical format of log event/source. Based on that it's not a good practice to name sourcetype by value of field (if I understood right what you are asking?). Instead of sourcetype you should use eventtype to separate those events inside sourcetype.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 09:28:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-want-source-type-separation-using-prop-conf/m-p/579362#M102285</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-12-28T09:28:19Z</dc:date>
    </item>
    <item>
      <title>Re: I want source type separation using prop.conf.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-want-source-type-separation-using-prop-conf/m-p/579372#M102286</link>
      <description>&lt;P&gt;I want to separate data whenever it comes in. Can similar effects be achieved using prop.conf or transaction.conf?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 11:16:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-want-source-type-separation-using-prop-conf/m-p/579372#M102286</guid>
      <dc:creator>noott211</dc:creator>
      <dc:date>2021-12-28T11:16:07Z</dc:date>
    </item>
    <item>
      <title>Re: I want source type separation using prop.conf.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/I-want-source-type-separation-using-prop-conf/m-p/579379#M102288</link>
      <description>&lt;P&gt;If I understood right your request you could do it with props.conf and transforms.conf (you need both). Look e.g. CLONE_SOURCETYPE for that. If there are lot of those values then it could be hard to manage all those versions.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Dec 2021 14:02:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/I-want-source-type-separation-using-prop-conf/m-p/579379#M102288</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-12-28T14:02:32Z</dc:date>
    </item>
  </channel>
</rss>

