All Apps and Add-ons

Splunk Add-on Builder: How does it determine which sourcetypes are available when adding sample data from Splunk?

masonmorales
Influencer

I've noticed that the vast majority of sourcetypes that I have indexed are not appearing in the "Select a sourcetype" drop-down menu when trying to add data from Splunk in the "Add Sample Data" step. How is the TA looking for sourcetypes to populate the drop-down menu with?

0 Karma

ehaddad_splunk
Splunk Employee
Splunk Employee

Sourcetypes are tied to data collection.
1- If it is mod input (built in Addon builder) it automatically shows on the list
2- If it is data indexed by Splunk core such HEC or syslog, you will need to import it by clicking on "import from splunk" button under "add sample data tab". Once you have imported it, it becomes visible to you in Addon builder so that you can apply knowledge ( field extraction and cim mapping) as part of the add-on
3- if you want to add file monitoring in addon, click on "upload from file", it becomes visible to you in Addon builder so that you can apply knowledge ( field extraction and cim mapping) as part of the add-on

This has become a common question we get, we will improve the UX to make it more clear in furture but hope this answers your question.

0 Karma

masonmorales
Influencer

Okay, so the problem is, I'm doing Step 2 and the sourcetype is not visible in the addon builder, so I'm not able to select it and move onto the Extract Fields step. I've tested this on both Linux+Windows installs of Splunk v6.5.2 with the same problem. Is this a bug then?

0 Karma

ehaddad_splunk
Splunk Employee
Splunk Employee

could be a bug. One thing i forgot to mention, make sure you have data in that sourcetype. If teh sourcetype has no data in the last week or month (forgot which one) then it wont be visible. Can you confirm the same?

0 Karma

masonmorales
Influencer

There are events in the past 24 hours with a matching sourcetype. The sourcetype does not appear in the "Select a sourcetype" drop-down menu on the Add Sample Data page after clicking the "Add From Splunk" button. I am using v2.0.0 of the addon.

0 Karma

ehaddad_splunk
Splunk Employee
Splunk Employee

ok sounds like a bug to me. We are releasing 2.1.0 very soon. I would try that version first and if problem persists, please file a bug. I will send you an email offline with early access.

0 Karma

masonmorales
Influencer

I have the same problem in 2.1.0. I'll open a support case.

0 Karma

damianpadden
Observer

Did u get to the solution for this. Running version 4.4 and have the exact issue.

 

Thanks

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...