<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic source type and event type in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/source-type-and-event-type/m-p/509911#M4644</link>
    <description>&lt;P&gt;I just want to know which filed name makes more sense to use for the segregation of the log type.&lt;/P&gt;&lt;P&gt;for example, we have Linux and windows logs. for separation of the log types in the report or alert which filed should be used. "source type" or "event type". and if you define it with a valid reason I would be very glad&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 19 Jul 2020 20:14:44 GMT</pubDate>
    <dc:creator>karakutu</dc:creator>
    <dc:date>2020-07-19T20:14:44Z</dc:date>
    <item>
      <title>source type and event type</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/source-type-and-event-type/m-p/509911#M4644</link>
      <description>&lt;P&gt;I just want to know which filed name makes more sense to use for the segregation of the log type.&lt;/P&gt;&lt;P&gt;for example, we have Linux and windows logs. for separation of the log types in the report or alert which filed should be used. "source type" or "event type". and if you define it with a valid reason I would be very glad&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jul 2020 20:14:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/source-type-and-event-type/m-p/509911#M4644</guid>
      <dc:creator>karakutu</dc:creator>
      <dc:date>2020-07-19T20:14:44Z</dc:date>
    </item>
    <item>
      <title>Re: source type and event type</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/source-type-and-event-type/m-p/509915#M4645</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Splexicon:Eventtype" target="_blank"&gt;https://docs.splunk.com/Splexicon:Eventtype&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Splexicon:Sourcetype" target="_blank"&gt;https://docs.splunk.com/Splexicon:Sourcetype&lt;/A&gt;&lt;/P&gt;&lt;P&gt;For your purposes,&amp;nbsp;&amp;nbsp;source type would be appropriate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jul 2020 20:24:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/source-type-and-event-type/m-p/509915#M4645</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-07-19T20:24:45Z</dc:date>
    </item>
    <item>
      <title>Re: source type and event type</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/source-type-and-event-type/m-p/509916#M4646</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;In personally I see that sourcetype formalise the content/lexical format of event. If two event has the same format then they should have same sourcetype (unless there are some other reason to name those differently).&amp;nbsp;&lt;/P&gt;&lt;P&gt;Eventtype is more wider concept. Quite often (but not mandatory) it contains also sourcetype, but also e.g. index(es), host(s), source(s), tag(s) etc. Basically it groups together events which belongs to specific (business) event(s) or something other contexts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both of those is really useful in correct context. In your case, it's impossible to say which one you are needing. Quite probably at least sourecetype, but probably also event types are needed/useful especially if you have several environments (dev, test, prod) where you could use one eventtype which content is different based on env (like macros).&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jul 2020 20:33:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/source-type-and-event-type/m-p/509916#M4646</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-07-19T20:33:44Z</dc:date>
    </item>
    <item>
      <title>Re: source type and event type</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/source-type-and-event-type/m-p/754676#M10497</link>
      <description>&lt;P&gt;this is like defining a word you don't know the meaning of with another word you don't know the meaning of&lt;/P&gt;</description>
      <pubDate>Thu, 23 Oct 2025 23:09:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/source-type-and-event-type/m-p/754676#M10497</guid>
      <dc:creator>Gregski11</dc:creator>
      <dc:date>2025-10-23T23:09:43Z</dc:date>
    </item>
  </channel>
</rss>

