<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is it possible to create another sourcetype under the same index from another sourcetype in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-create-another-sourcetype-under-the-same-index/m-p/558279#M92369</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230955"&gt;@oylkm&lt;/a&gt;&amp;nbsp;inputs always on host where data present.&amp;nbsp; Splunk by default ships with few generic sourcetypes which one you are after?&lt;/P&gt;&lt;P&gt;default generic sourcetypes are usually present under system/default dir in props.conf, custom sourcetypes Splunk recommends to put it under system/local or app_name/local directory and if your splunk environment is distributed then you have to put them under HF, if&amp;nbsp; there is no HF put them on indexers. It does work with new sourcetypes (define your own name) it just to be deployed under right place and having correct line_breaking and timestamp extractions.&lt;/P&gt;&lt;P&gt;Since you are going to use settings of default sourcetypes, just changing the name it should work fine. You can read more here -&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.2.2105/Data/Whysourcetypesmatter" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.2.2105/Data/Whysourcetypesmatter&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;An upvote would be appreciated and Accept solution if it helps!&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jul 2021 08:13:55 GMT</pubDate>
    <dc:creator>venkatasri</dc:creator>
    <dc:date>2021-07-05T08:13:55Z</dc:date>
    <item>
      <title>Is it possible to create another sourcetype under the same index from another sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-create-another-sourcetype-under-the-same-index/m-p/558263#M92363</link>
      <description>&lt;P&gt;Hello Guys, newbie here.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've got data that's being sent to a generic sourcetype and I want to carve out another sourcetype based on this particular one. Is that possible and are there any ramifications to note on doing this?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 02:31:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-create-another-sourcetype-under-the-same-index/m-p/558263#M92363</guid>
      <dc:creator>oylkm</dc:creator>
      <dc:date>2021-07-05T02:31:43Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create another sourcetype under the same index from another sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-create-another-sourcetype-under-the-same-index/m-p/558264#M92364</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230955"&gt;@oylkm&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can create your own sourcetype from default generic sourcetype. Just goto props.conf and copy contents under generic sourcetype and create your own. you can create new props.conf under $SPLUNK_HOME/system/local OR&amp;nbsp;$SPLUNK_HOME/etc/apps/&amp;lt;your_app_name&amp;gt;/local. The new props shall be deployed to HF/indexer depends on your Splunk infra.&lt;/P&gt;&lt;P&gt;change generic to new sourcetype in inputs.conf at origin.&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;An upvote would be appreciated and Accept solution if it helps!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 02:42:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-create-another-sourcetype-under-the-same-index/m-p/558264#M92364</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-05T02:42:42Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create another sourcetype under the same index from another sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-create-another-sourcetype-under-the-same-index/m-p/558274#M92367</link>
      <description>&lt;P&gt;The data inputs is actually defined in inputs.conf to monitor a location, attach to an index/sourcetype and nothing is defined in the current props.conf. Will it still work if I create a new props.conf and define a separate settings?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 07:41:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-create-another-sourcetype-under-the-same-index/m-p/558274#M92367</guid>
      <dc:creator>oylkm</dc:creator>
      <dc:date>2021-07-05T07:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create another sourcetype under the same index from another sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-create-another-sourcetype-under-the-same-index/m-p/558275#M92368</link>
      <description>&lt;P&gt;I'm thinking along the lines of taking a sample of the new data that I want to see in the new sourcetype and define it but any recommendations is fine.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 07:42:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-create-another-sourcetype-under-the-same-index/m-p/558275#M92368</guid>
      <dc:creator>oylkm</dc:creator>
      <dc:date>2021-07-05T07:42:44Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create another sourcetype under the same index from another sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-create-another-sourcetype-under-the-same-index/m-p/558279#M92369</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230955"&gt;@oylkm&lt;/a&gt;&amp;nbsp;inputs always on host where data present.&amp;nbsp; Splunk by default ships with few generic sourcetypes which one you are after?&lt;/P&gt;&lt;P&gt;default generic sourcetypes are usually present under system/default dir in props.conf, custom sourcetypes Splunk recommends to put it under system/local or app_name/local directory and if your splunk environment is distributed then you have to put them under HF, if&amp;nbsp; there is no HF put them on indexers. It does work with new sourcetypes (define your own name) it just to be deployed under right place and having correct line_breaking and timestamp extractions.&lt;/P&gt;&lt;P&gt;Since you are going to use settings of default sourcetypes, just changing the name it should work fine. You can read more here -&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/8.2.2105/Data/Whysourcetypesmatter" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/8.2.2105/Data/Whysourcetypesmatter&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;An upvote would be appreciated and Accept solution if it helps!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 08:13:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-create-another-sourcetype-under-the-same-index/m-p/558279#M92369</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-05T08:13:55Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create another sourcetype under the same index from another sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-create-another-sourcetype-under-the-same-index/m-p/558283#M92370</link>
      <description>&lt;P&gt;It's not really a generic log per se, the index and sourcetype is based on F5 logs and I want to carve out a new sourcetype to see a different type of data and we are not using the splunkbase app for this.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 08:35:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-create-another-sourcetype-under-the-same-index/m-p/558283#M92370</guid>
      <dc:creator>oylkm</dc:creator>
      <dc:date>2021-07-05T08:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create another sourcetype under the same index from another sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-create-another-sourcetype-under-the-same-index/m-p/558286#M92371</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230955"&gt;@oylkm&lt;/a&gt;&amp;nbsp;then you might need to define line breaking and timestamp extraction. If there is a addon for F5 in splunkbase it might be already having sourcetype definitions that you are after.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jul 2021 08:52:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-create-another-sourcetype-under-the-same-index/m-p/558286#M92371</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-05T08:52:31Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create another sourcetype under the same index from another sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-create-another-sourcetype-under-the-same-index/m-p/558370#M92381</link>
      <description>&lt;P&gt;So this is what I've come up with on the base sourcetype.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[apm:apm:syslog]&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;SHOULD_LINEMERGE = false&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;BREAK_ONLY_BEFORE_DATE = true&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;TZ = Newzealand/Auckland&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Are you suggesting I create another props.conf file under the same app? If so how do I make it reference the same index as well. I want to call the new sourcetype apm:apm:syslog:ltm.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 08:47:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-create-another-sourcetype-under-the-same-index/m-p/558370#M92381</guid>
      <dc:creator>oylkm</dc:creator>
      <dc:date>2021-07-06T08:47:08Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create another sourcetype under the same index from another sourcetype</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-create-another-sourcetype-under-the-same-index/m-p/558371#M92382</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/230955"&gt;@oylkm&lt;/a&gt;&amp;nbsp;you can keep it same app under /local dir.. not in default dir it works but local is suggested. You might need to test new sourcetype settings.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Jul 2021 08:56:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-it-possible-to-create-another-sourcetype-under-the-same-index/m-p/558371#M92382</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-07-06T08:56:09Z</dc:date>
    </item>
  </channel>
</rss>

