<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Defining custom sourcetype based on log file path in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Defining-custom-sourcetype-based-on-log-file-path/m-p/30639#M5380</link>
    <description>&lt;P&gt;Are you using Splunk's deployment server to manage forwarder configurations? That should be the best way to solve the issue. &lt;/P&gt;

&lt;P&gt;Otherwise, you could use props/transforms stanzas to override the sourcetype assignment at runtime. You could run a regex on the "source" field and assign a predefined sourcetype if the event matches the regex. 
You can find lots of details here: &lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Advancedsourcetypeoverrides" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/Admin/Advancedsourcetypeoverrides&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 23 Jan 2011 01:09:23 GMT</pubDate>
    <dc:creator>Paolo_Prigione</dc:creator>
    <dc:date>2011-01-23T01:09:23Z</dc:date>
    <item>
      <title>Defining custom sourcetype based on log file path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Defining-custom-sourcetype-based-on-log-file-path/m-p/30638#M5379</link>
      <description>&lt;P&gt;We have a forwarder/receiver topology configured here.  Each of the 200 or so servers have a light forwarder their info to the main indexer/receiver.&lt;/P&gt;

&lt;P&gt;My challenge is that many of these machines are generating a custom source type.&lt;/P&gt;

&lt;P&gt;We are currently defining the custom source types in a .conf file at the forwarding machine.  unfortunately, this creates somewhat of a management problem given the number of machines.&lt;/P&gt;

&lt;P&gt;is there way to define custom source types in .conf at the Receiver/Indexer?&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jan 2011 23:20:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Defining-custom-sourcetype-based-on-log-file-path/m-p/30638#M5379</guid>
      <dc:creator>jcbrendsel</dc:creator>
      <dc:date>2011-01-22T23:20:28Z</dc:date>
    </item>
    <item>
      <title>Re: Defining custom sourcetype based on log file path</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Defining-custom-sourcetype-based-on-log-file-path/m-p/30639#M5380</link>
      <description>&lt;P&gt;Are you using Splunk's deployment server to manage forwarder configurations? That should be the best way to solve the issue. &lt;/P&gt;

&lt;P&gt;Otherwise, you could use props/transforms stanzas to override the sourcetype assignment at runtime. You could run a regex on the "source" field and assign a predefined sourcetype if the event matches the regex. 
You can find lots of details here: &lt;A href="http://www.splunk.com/base/Documentation/latest/Admin/Advancedsourcetypeoverrides" rel="nofollow"&gt;http://www.splunk.com/base/Documentation/latest/Admin/Advancedsourcetypeoverrides&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 23 Jan 2011 01:09:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Defining-custom-sourcetype-based-on-log-file-path/m-p/30639#M5380</guid>
      <dc:creator>Paolo_Prigione</dc:creator>
      <dc:date>2011-01-23T01:09:23Z</dc:date>
    </item>
  </channel>
</rss>

