All Apps and Add-ons

How to Config sourcetype for kafka topic inputs

ross0nero
Explorer

I can't find place to set sourcetype for different kafka topic input,how can I config it for event breaker or timestamp modify?
thank you

0 Karma

rpille_splunk
Splunk Employee
Splunk Employee

Thanks for your question, Ross. The add-on automatically sets the source type for you based on the data source and the log format. The source types, along with their timestamp methods, are documented here: http://docs.splunk.com/Documentation/AddOns/latest/Kafka/Sourcetypes

Knowledge management in the TA depends on these source types, so you should not change them without also then modifying props.conf. If you find you need to further adjust event breaking or timestamps, you can do that manually in props.conf. http://docs.splunk.com/Documentation/Splunk/latest/admin/Propsconf

0 Karma

ross0nero
Explorer

Hello,rpille,Kafka topic data collected through a modular input use default sourcetype kafka:topicEvent
If I have two different log in kafka topic,how can I adjust breaking or timestamps two different log type with same sourcetype?
thank you

0 Karma

rpille_splunk
Splunk Employee
Splunk Employee

I see. Yes, the add-on is content-agnostic for whatever your payloads may be in your Kafka topics, so it doesn't do any detection for different data types. You can achieve this manually in props.conf. Here is the advanced overrides page for reference: http://docs.splunk.com/Documentation/Splunk/6.3.3/Data/Advancedsourcetypeoverrides

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...