Getting Data In

Custom name for Sourcetype

ghannemann
Engager

Hi

I have a forwarder pushing java log data to an indexer. The inputs on the index was set to log4j. However in the basic summary screen, the sourcetype is shown as server.
Why is this?

Is there anyway to rename this sourcetype, or creating based on an existing one with a different name?

Regards,
Gerhard

Tags (1)
0 Karma

ghannemann
Engager

Whoops, sorry, yes I did mean sourcetype, not index, (had other questions that - mix up of terms). I was trying to see if I could create my own sourcetypes based on existing ones.

0 Karma

sbrant_splunk
Splunk Employee
Splunk Employee

You can specify the sourcetype in a few places.

On the forwarder, in inputs.conf:

[monitor://path to log file]
sourcetype=log4j

OR

On the indexer, in props.conf:

[source::full path to log file]
sourcetype=log4j
0 Karma

ghannemann
Engager

Thank you.
I also found it useful to set sourcetype on the forward (universal forwarder) and the receiver as well.

0 Karma

sbrant_splunk
Splunk Employee
Splunk Employee

Your description is a bit confusing. You say that "the inputs on the index was set to log4j", do you mean that the inputs.conf file on the forwarder, within the stanza collecting this file, has a line that says "sourcetype=log4j"?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Fuel Your Journey: What’s Waiting for You at the .conf26 Acceleration Station

Navigating the show floor at .conf26 isn't just about keynotes and technical breakout sessions; it's also ...

Join the Final Session of the Data Management & Federation Bootcamp Series

Over the past three sessions of the Data Management & Federation Bootcamp Series, we've explored how to build ...

From Data to Insight: Announcing the Winners of the Splunk Dashboard Contest

Hi Splunkers, First off, thank you to everyone who participated in our very first From Data to Insight: The ...