Getting Data In

Extracting sourcetype from source /tmp/csv/file1

hylam
Contributor

The sourcetype should be csv or tsv or psv, depending on the full path in the source field. For hosts we have host_regex and host_segment. Do we have sourcetype_regex or sourcetype_segment? Thx.

/tmp/csv/file1
/tmp/csv/file2
/tmp/tsv/file3
/tmp/tsv/file4
/tmp/psv/file5
/tmp/psv/file6

Tags (1)
0 Karma
1 Solution

esix_splunk
Splunk Employee
Splunk Employee

We dont have this ability now in Splunk. However, you can further filter the sourcetype by source via transforms and searching a regex against the meta data. This article has a good example -

https://answers.splunk.com/answers/112471/changing-sourcetype-with-regex.html

View solution in original post

esix_splunk
Splunk Employee
Splunk Employee

We dont have this ability now in Splunk. However, you can further filter the sourcetype by source via transforms and searching a regex against the meta data. This article has a good example -

https://answers.splunk.com/answers/112471/changing-sourcetype-with-regex.html

Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...