<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Custom name for Sourcetype in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Custom-name-for-Sourcetype/m-p/44829#M8404</link>
    <description>&lt;P&gt;You can specify the sourcetype in a few places.&lt;/P&gt;

&lt;P&gt;On the forwarder, in inputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://path to log file]
sourcetype=log4j
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;OR&lt;/P&gt;

&lt;P&gt;On the indexer, in props.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[source::full path to log file]
sourcetype=log4j
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Wed, 27 Feb 2013 03:47:08 GMT</pubDate>
    <dc:creator>sbrant_splunk</dc:creator>
    <dc:date>2013-02-27T03:47:08Z</dc:date>
    <item>
      <title>Custom name for Sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Custom-name-for-Sourcetype/m-p/44827#M8402</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;I have a forwarder pushing java log data to an indexer.  The inputs on the index was set to log4j.  However in the basic summary screen, the sourcetype is shown as server.&lt;BR /&gt;
Why is this?&lt;/P&gt;

&lt;P&gt;Is there anyway to rename this sourcetype, or creating based on an existing one with a different name?&lt;/P&gt;

&lt;P&gt;Regards,&lt;BR /&gt;
Gerhard&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2013 01:51:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Custom-name-for-Sourcetype/m-p/44827#M8402</guid>
      <dc:creator>ghannemann</dc:creator>
      <dc:date>2013-02-27T01:51:08Z</dc:date>
    </item>
    <item>
      <title>Re: Custom name for Sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Custom-name-for-Sourcetype/m-p/44828#M8403</link>
      <description>&lt;P&gt;Your description is a bit confusing.  You say that "the inputs on the index was set to log4j", do you mean that the inputs.conf file on the forwarder, within the stanza collecting this file, has a line that says "sourcetype=log4j"?&lt;/P&gt;</description>
      <pubDate>Wed, 27 Feb 2013 03:38:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Custom-name-for-Sourcetype/m-p/44828#M8403</guid>
      <dc:creator>sbrant_splunk</dc:creator>
      <dc:date>2013-02-27T03:38:08Z</dc:date>
    </item>
    <item>
      <title>Re: Custom name for Sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Custom-name-for-Sourcetype/m-p/44829#M8404</link>
      <description>&lt;P&gt;You can specify the sourcetype in a few places.&lt;/P&gt;

&lt;P&gt;On the forwarder, in inputs.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[monitor://path to log file]
sourcetype=log4j
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;OR&lt;/P&gt;

&lt;P&gt;On the indexer, in props.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[source::full path to log file]
sourcetype=log4j
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 27 Feb 2013 03:47:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Custom-name-for-Sourcetype/m-p/44829#M8404</guid>
      <dc:creator>sbrant_splunk</dc:creator>
      <dc:date>2013-02-27T03:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: Custom name for Sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Custom-name-for-Sourcetype/m-p/44830#M8405</link>
      <description>&lt;P&gt;Whoops, sorry, yes I did mean sourcetype, not index, (had other questions that - mix up of terms).  I was trying to see if I could create my own sourcetypes based on existing ones.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2013 00:20:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Custom-name-for-Sourcetype/m-p/44830#M8405</guid>
      <dc:creator>ghannemann</dc:creator>
      <dc:date>2013-03-12T00:20:58Z</dc:date>
    </item>
    <item>
      <title>Re: Custom name for Sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Custom-name-for-Sourcetype/m-p/44831#M8406</link>
      <description>&lt;P&gt;Thank you.&lt;BR /&gt;
I also found it useful to set sourcetype on the forward (universal forwarder) and the receiver as well.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2013 00:22:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Custom-name-for-Sourcetype/m-p/44831#M8406</guid>
      <dc:creator>ghannemann</dc:creator>
      <dc:date>2013-03-12T00:22:11Z</dc:date>
    </item>
  </channel>
</rss>

