<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to create a New Source Types in SPLUNK? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/How-to-create-a-New-Source-Types-in-SPLUNK/m-p/591131#M11369</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I know we can use SPLUNK GUI to create source types. But how I would create a new source type from CLI or using props.conf file. Any help will be highly appreciated, thank you.&lt;/P&gt;
&lt;P&gt;Does this props.conf&amp;nbsp; is going to create&amp;nbsp; new source type test:audit&amp;nbsp; if it doesn't exist&lt;/P&gt;
&lt;P&gt;[test:audit]&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;SHOULD_LINEMERGE=false
LINE_BREAKER=([\r\n]*)&amp;lt;MODTRANSAUDTRL&amp;gt;
TIME_PREFIX= &amp;lt;TIMESTAMP&amp;gt;
TIME_FORMAT=%Y-%m-%dT%H:%M:%S.%2N
MAX_TIMESTAMP_LOOKAHEAD=24
TRUNCATE=1000&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 29 Mar 2022 13:06:41 GMT</pubDate>
    <dc:creator>SplunkDash</dc:creator>
    <dc:date>2022-03-29T13:06:41Z</dc:date>
    <item>
      <title>How to create a New Source Types in SPLUNK?</title>
      <link>https://community.splunk.com/t5/Installation/How-to-create-a-New-Source-Types-in-SPLUNK/m-p/591131#M11369</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I know we can use SPLUNK GUI to create source types. But how I would create a new source type from CLI or using props.conf file. Any help will be highly appreciated, thank you.&lt;/P&gt;
&lt;P&gt;Does this props.conf&amp;nbsp; is going to create&amp;nbsp; new source type test:audit&amp;nbsp; if it doesn't exist&lt;/P&gt;
&lt;P&gt;[test:audit]&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;SHOULD_LINEMERGE=false
LINE_BREAKER=([\r\n]*)&amp;lt;MODTRANSAUDTRL&amp;gt;
TIME_PREFIX= &amp;lt;TIMESTAMP&amp;gt;
TIME_FORMAT=%Y-%m-%dT%H:%M:%S.%2N
MAX_TIMESTAMP_LOOKAHEAD=24
TRUNCATE=1000&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 13:06:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-create-a-New-Source-Types-in-SPLUNK/m-p/591131#M11369</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2022-03-29T13:06:41Z</dc:date>
    </item>
    <item>
      <title>Re: Create a New Source Types in SPLUNK</title>
      <link>https://community.splunk.com/t5/Installation/How-to-create-a-New-Source-Types-in-SPLUNK/m-p/591132#M11370</link>
      <description>&lt;P&gt;Sourcetype is just a value. It's just that using this value splunk decides what to do with an event. So in general, anything that you associate with an event on input is a sourcetype. Then you're only telling splunk what to do with event which has this sourcetype by means of props and transforms.&lt;/P&gt;&lt;P&gt;So you don't have to "define" a sourcetype. You can set it to anything in your inputs.conf (as long as it's syntactically correct). Then you just have to set proper props.conf for handling this sourcetype.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 19:04:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-create-a-New-Source-Types-in-SPLUNK/m-p/591132#M11370</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-28T19:04:25Z</dc:date>
    </item>
    <item>
      <title>Re: Create a New Source Types in SPLUNK</title>
      <link>https://community.splunk.com/t5/Installation/How-to-create-a-New-Source-Types-in-SPLUNK/m-p/591136#M11371</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you so much for your quick response appreciates it. If this is the case what is there in the GUI to create sourcetype in SPLUNK? Thank you again.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 19:14:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-create-a-New-Source-Types-in-SPLUNK/m-p/591136#M11371</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2022-03-28T19:14:48Z</dc:date>
    </item>
    <item>
      <title>Re: Create a New Source Types in SPLUNK</title>
      <link>https://community.splunk.com/t5/Installation/How-to-create-a-New-Source-Types-in-SPLUNK/m-p/591137#M11372</link>
      <description>&lt;P&gt;The web client treats it a bit differently (although the underlying mechanics stay the same).&lt;/P&gt;&lt;P&gt;If you "create a sourcetype" in the web client, splunk defines some parsing settings for it (like line/event breaking, timestamp recognition, kv mode and such) - the stuff that you typically do in props.conf - so you can then chose this set of settings when creating an input. It's the web client that enforces this "consistency". It's just one of convenience features in splunk web aimed at less experienced users &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;In other words, whereas in config files you can do whatever stupidity you want &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt; like in unix, the webui holds your hand like windows &lt;span class="lia-unicode-emoji" title=":grinning_face_with_smiling_eyes:"&gt;😄&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But even the webui does this in a limited way. When you create an input you have to either select a sourcetype from the predefined list or create a new definition. But when you click on an already created input, you can change the sourcetype value to whatever you want regardless of whether you have it "defined" or not (in other words, whether ther are settings for parsing this sourcetype or not).&lt;/P&gt;</description>
      <pubDate>Mon, 28 Mar 2022 19:44:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-create-a-New-Source-Types-in-SPLUNK/m-p/591137#M11372</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-28T19:44:03Z</dc:date>
    </item>
    <item>
      <title>Re: Create a New Source Types in SPLUNK</title>
      <link>https://community.splunk.com/t5/Installation/How-to-create-a-New-Source-Types-in-SPLUNK/m-p/591166#M11374</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;I created source type based on your instructions. Thank you so much, appreciated. But getting error message and also getting 1 event instead of 10 events. I am not sure what's the mistake I have done. My props/inputs configuration files and sample source data are given below. Any help will be highly appreciated. Thank you again.&lt;/P&gt;&lt;P&gt;[oswindows_companion:preamble]&lt;BR /&gt;SHOULD_LINEMERGE=false&lt;BR /&gt;CHARSET=UTF-8&lt;BR /&gt;INDEXED_EXTRACTIONS=csv&lt;BR /&gt;category=Structured&lt;BR /&gt;TIMESTAMP_FIELDS=Test Date&lt;BR /&gt;TIME_FORMAT=%Y-%m-%d %H:%M:%S&lt;BR /&gt;HEADER_FIELD_LINE_NUMBER=1&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[monitor:///opt/splunk/var/log/windows_parsed_reports/companion_preamble/*.csv]&lt;BR /&gt;disabled=false&lt;BR /&gt;sourcetype=oswindows_companion:preamble&lt;BR /&gt;index=oswindows&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="SplunkDash_0-1648527435127.png" style="width: 737px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/18801i97483ED096A0F0B5/image-dimensions/737x72?v=v2" width="737" height="72" role="button" title="SplunkDash_0-1648527435127.png" alt="SplunkDash_0-1648527435127.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 04:19:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-create-a-New-Source-Types-in-SPLUNK/m-p/591166#M11374</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2022-03-29T04:19:12Z</dc:date>
    </item>
    <item>
      <title>Re: Create a New Source Types in SPLUNK</title>
      <link>https://community.splunk.com/t5/Installation/How-to-create-a-New-Source-Types-in-SPLUNK/m-p/591186#M11375</link>
      <description>&lt;P&gt;If&amp;nbsp; this is your literal input file line, you definitely have date formatting inconsistent with the props.conf definition.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 06:16:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-create-a-New-Source-Types-in-SPLUNK/m-p/591186#M11375</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-29T06:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: Create a New Source Types in SPLUNK</title>
      <link>https://community.splunk.com/t5/Installation/How-to-create-a-New-Source-Types-in-SPLUNK/m-p/591363#M11379</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Thank you so much for your feedback. What should I use for this?&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;TIME_FORMAT=%Y/%m/%d %H:%M:%S&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;It's not working as well&lt;/P&gt;</description>
      <pubDate>Tue, 29 Mar 2022 23:16:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-create-a-New-Source-Types-in-SPLUNK/m-p/591363#M11379</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2022-03-29T23:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: Create a New Source Types in SPLUNK</title>
      <link>https://community.splunk.com/t5/Installation/How-to-create-a-New-Source-Types-in-SPLUNK/m-p/591459#M11380</link>
      <description>&lt;P&gt;The line from your input data doesn't show the seconds so you can't include ":%S" in the data format because it will never match anything. Also - your with your time format you should have 2022/02/24 whereas you have this illogical american date format 02/24/2022.&lt;/P&gt;&lt;P&gt;Try &lt;STRONG&gt;%m/%d/%Y %H:%M&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Should work but can cause problems if you have 12-hour clock without explicitly provided AM/PM.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 09:47:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-create-a-New-Source-Types-in-SPLUNK/m-p/591459#M11380</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2022-03-30T09:47:13Z</dc:date>
    </item>
    <item>
      <title>Re: Create a New Source Types in SPLUNK</title>
      <link>https://community.splunk.com/t5/Installation/How-to-create-a-New-Source-Types-in-SPLUNK/m-p/591532#M11387</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you so much. I tried&lt;/P&gt;&lt;P&gt;%m/%d/%Y %H:%M, still getting error message, but&amp;nbsp; not sure why getting better result using %/m%/d%/Y %H:%M.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Mar 2022 14:38:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-create-a-New-Source-Types-in-SPLUNK/m-p/591532#M11387</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2022-03-30T14:38:59Z</dc:date>
    </item>
  </channel>
</rss>

