Getting Data In

Best Practice for Creating New Sourcetype - Splunk Cloud

dfurtaw
Path Finder

Hi All,

I'm a new Splunk admin working inside of a pretty large Splunk Cloud environment. Historically, the folks on the admin/engineering team have defined custom sourcetypes inside of a custom application that is installed on our SH's and indexers. They have created the sourcetype by adding a stanza in the props.conf and configuring the flags within the stanza.

I'm all for best practices and I wanted to see if the Splunk community could weigh in and point me in the right direction of how I should be creating new custom sourcetypes. Would the best way be to create the sourcetype in the GUI? If so, which app should I be saving the sourcetype in?

I could continue using the current process, although this process requires a rolling restart of our indexers and SH, which causes an outage during each update to the custom app. If there is any other information I should be including, please let me know.

Thank you 🙂

0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

IMO, you should maintain the current practice. Using the GUI means changes will be stored in an app's local directory and so will always override any change pushed by a new version of the app. It also means your changes will not be part of the app's Git repository, if you have one.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

IMO, you should maintain the current practice. Using the GUI means changes will be stored in an app's local directory and so will always override any change pushed by a new version of the app. It also means your changes will not be part of the app's Git repository, if you have one.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

What's New in Splunk Cloud Platform 9.3.2411?

Hey Splunky People! We are excited to share the latest updates in Splunk Cloud Platform 9.3.2411. This release ...

Buttercup Games: Further Dashboarding Techniques (Part 6)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...