Deployment Architecture

Can I have 2 sourcetype in one?

Jeanmichou
Loves-to-Learn Lots

Hello,

after having redeployed my UF (with a props because my logs are in csv). I end up with my new parsing mixed with the old parsing. Does it speak to you?

In my case, I have my logs which end up with a non-existent header (it takes the 1st line of the csv which is a log). And at the same time it also parses correctly (because I modified the problem).

THANKS

Labels (2)
0 Karma

Jeanmichou
Loves-to-Learn Lots

I have the impression that it caches the old sourcetype when it no longer exists

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...