Deployment Architecture

Can I have 2 sourcetype in one?

Jeanmichou
Loves-to-Learn Lots

Hello,

after having redeployed my UF (with a props because my logs are in csv). I end up with my new parsing mixed with the old parsing. Does it speak to you?

In my case, I have my logs which end up with a non-existent header (it takes the 1st line of the csv which is a log). And at the same time it also parses correctly (because I modified the problem).

THANKS

Labels (2)
0 Karma

Jeanmichou
Loves-to-Learn Lots

I have the impression that it caches the old sourcetype when it no longer exists

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...