<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: sourcetypes in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/sourcetypes/m-p/528781#M149293</link>
    <description>&lt;P&gt;AFAIK, There is no direct way to identify this. you can identify using&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal group=per_sourcetype_thruput sourcetype=splunkd host=&amp;lt;excludeyourindexers&amp;gt; | stats count by host,series
| table host,series | rename series as sourcetype&lt;/LI-CODE&gt;</description>
    <pubDate>Tue, 10 Nov 2020 07:05:04 GMT</pubDate>
    <dc:creator>thambisetty</dc:creator>
    <dc:date>2020-11-10T07:05:04Z</dc:date>
    <item>
      <title>sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/sourcetypes/m-p/528773#M149288</link>
      <description>&lt;P&gt;Is there a way to tell which method a sourcetype is using to get data into splunk?&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example, suppose I look at the sourcetype of an index named main&lt;BR /&gt;&lt;BR /&gt;|metadata type=sourcetype index=main&lt;/P&gt;&lt;P&gt;It display a list of sourcetypes but I want to know if those sourtypes of syslog, from a heavy forwarder, or from a universal forwarder.&amp;nbsp; Is that possible?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2020 03:27:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/sourcetypes/m-p/528773#M149288</guid>
      <dc:creator>verifi81</dc:creator>
      <dc:date>2020-11-10T03:27:20Z</dc:date>
    </item>
    <item>
      <title>Re: sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/sourcetypes/m-p/528781#M149293</link>
      <description>&lt;P&gt;AFAIK, There is no direct way to identify this. you can identify using&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;index=_internal group=per_sourcetype_thruput sourcetype=splunkd host=&amp;lt;excludeyourindexers&amp;gt; | stats count by host,series
| table host,series | rename series as sourcetype&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 10 Nov 2020 07:05:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/sourcetypes/m-p/528781#M149293</guid>
      <dc:creator>thambisetty</dc:creator>
      <dc:date>2020-11-10T07:05:04Z</dc:date>
    </item>
    <item>
      <title>Re: sourcetypes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/sourcetypes/m-p/528786#M149296</link>
      <description>That's good starting point. Unfortunately it shows only 10 most busiest sourcetypes by default.&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.0/Troubleshooting/Aboutmetricslog" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/Troubleshooting/Aboutmetricslog&lt;/A&gt;&lt;BR /&gt;Unfortunately I couldn't recall any better way at this point.</description>
      <pubDate>Tue, 10 Nov 2020 07:22:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/sourcetypes/m-p/528786#M149296</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2020-11-10T07:22:27Z</dc:date>
    </item>
  </channel>
</rss>

