Getting Data In

Best Practice for Creating New Sourcetype - Splunk Cloud

dfurtaw
Path Finder

Hi All,

I'm a new Splunk admin working inside of a pretty large Splunk Cloud environment. Historically, the folks on the admin/engineering team have defined custom sourcetypes inside of a custom application that is installed on our SH's and indexers. They have created the sourcetype by adding a stanza in the props.conf and configuring the flags within the stanza.

I'm all for best practices and I wanted to see if the Splunk community could weigh in and point me in the right direction of how I should be creating new custom sourcetypes. Would the best way be to create the sourcetype in the GUI? If so, which app should I be saving the sourcetype in?

I could continue using the current process, although this process requires a rolling restart of our indexers and SH, which causes an outage during each update to the custom app. If there is any other information I should be including, please let me know.

Thank you 🙂

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

IMO, you should maintain the current practice. Using the GUI means changes will be stored in an app's local directory and so will always override any change pushed by a new version of the app. It also means your changes will not be part of the app's Git repository, if you have one.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

IMO, you should maintain the current practice. Using the GUI means changes will be stored in an app's local directory and so will always override any change pushed by a new version of the app. It also means your changes will not be part of the app's Git repository, if you have one.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...