<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to split single sourcetype in multiple ones based on json field value? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-split-single-sourcetype-in-multiple-ones-based-on-json/m-p/623756#M107309</link>
    <description>&lt;P&gt;You cannot rename the source type for data that has already been indexed. You can do some things at search time, but since that is inefficient I won't go into it. Your best bet is likely sending the data feed to a heavy forwarder, setting the source types appropriately (inputs, props, transforms), and then kicking it to the indexers.&lt;/P&gt;</description>
    <pubDate>Thu, 08 Dec 2022 20:18:58 GMT</pubDate>
    <dc:creator>Atriarc</dc:creator>
    <dc:date>2022-12-08T20:18:58Z</dc:date>
    <item>
      <title>How to split single sourcetype in multiple ones based on json field value?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-split-single-sourcetype-in-multiple-ones-based-on-json/m-p/623741#M107307</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;
&lt;P&gt;recently my customer asked me to integrate different JSON log sources (VPN concentrator, WAF and Load Balancers) comeing from only one Azure event hub. I onboarded it using the Splunk Add-on for Microsoft Cloud Services (&lt;A href="https://splunkbase.splunk.com/app/3110" target="_blank" rel="noopener"&gt;https://splunkbase.splunk.com/app/3110&lt;/A&gt;) from the Inputs Data Manager Instance (IDM) and I selected the deafult sourcetype "mscs:azure:eventhub". At this point I need to split this sourcetype in three new ones, one for each log type (VPN concentrator, WAF and Load Balancers) distinguishing them and creating custom field extractions and so on for the Data Models. I found a field "category"&amp;nbsp; within the JSON logs which can be used as splitting criteria:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="marco_massari11_0-1670517468037.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/22937i711C6CAC700547EA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="marco_massari11_0-1670517468037.png" alt="marco_massari11_0-1670517468037.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Have you any idea to do that?&lt;/P&gt;
&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 19:36:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-split-single-sourcetype-in-multiple-ones-based-on-json/m-p/623741#M107307</guid>
      <dc:creator>marco_massari11</dc:creator>
      <dc:date>2022-12-08T19:36:06Z</dc:date>
    </item>
    <item>
      <title>Re: How to split single sourcetype in multiple ones based on json field value?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-split-single-sourcetype-in-multiple-ones-based-on-json/m-p/623756#M107309</link>
      <description>&lt;P&gt;You cannot rename the source type for data that has already been indexed. You can do some things at search time, but since that is inefficient I won't go into it. Your best bet is likely sending the data feed to a heavy forwarder, setting the source types appropriately (inputs, props, transforms), and then kicking it to the indexers.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 20:18:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-split-single-sourcetype-in-multiple-ones-based-on-json/m-p/623756#M107309</guid>
      <dc:creator>Atriarc</dc:creator>
      <dc:date>2022-12-08T20:18:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to split single sourcetype in multiple ones based on json field value?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-split-single-sourcetype-in-multiple-ones-based-on-json/m-p/623761#M107310</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/237218"&gt;@Atriarc&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;my idea was to configure such a parser, maybe in the indxer before indexing.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Dec 2022 21:22:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-split-single-sourcetype-in-multiple-ones-based-on-json/m-p/623761#M107310</guid>
      <dc:creator>marco_massari11</dc:creator>
      <dc:date>2022-12-08T21:22:39Z</dc:date>
    </item>
  </channel>
</rss>

