Getting Data In

Creating Sourcetype form event data not data

robertlynch2020
Motivator

Hi

I am sending open telemetry Log data to Splunk.

I am sending 3 different types of logs to one index and to one source type (For the moment)

Is it possible to receive this data into Splunk and then create 3 different types of Sourcetypes, based on the event data, not the data?

 splunk_hec/logs: # pushed to splunk
    token: "ac3fa6bf-f9df-4757-a5e5-9ee7bf23160d"
    endpoint: "https://dell425srv:9088/services/collector"
    source: "mx"
    sourcetype: "otel"
    index: "murex_logs"
    tls:
      insecure_skip_verify: true

 

In the below image we can see the event data is called log.type.

There can be three of them. I need to make 3 source types from these 3.

robertlynch2020_1-1652715852621.png

 

robertlynch2020_0-1652715676536.png

Normally I would use a transform, but I think I can only use that on the data, not the event data?

Any help would be great 

Thanks in advance

Robbie

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...

Reminder! Splunk Love Promo: $25 Visa Gift Card for Your Honest SOAR Review With ...

We recently launched our first Splunk Love Special, and it's gone phenomenally well, so we're doing it again, ...