Getting Data In

How do I test sourcetyping before I index

rroberts
Splunk Employee
Splunk Employee

How can I see how Splunk is going to handle a particular dataset BEFORE I actually input? For example: If I monitor a log what sourcetype is splunk going to tag the events with?

Tags (2)
0 Karma
1 Solution

rroberts
Splunk Employee
Splunk Employee

Check the CLI test. From $SPLUNK_HOME/bin Check help for test... ./splunk test help ./splunk test sourcetype

Example:

./splunk test sourcetype /opt/tradelog/trade_entries.log

PROPERTIES OF /opt/log/tradelog/trade_entries.log
Attr:ANNOTATE_PUNCT True
Attr:BREAK_ONLY_BEFORE
Attr:BREAK_ONLY_BEFORE_DATE True
Attr:CHARSET UTF-8
Attr:DATETIME_CONFIG /etc/datetime.xml
Attr:HEADER_MODE
Attr:LEARN_SOURCETYPE true
Attr:LINE_BREAKER_LOOKBEHIND 100
Attr:MAX_DAYS_AGO 2000
Attr:MAX_DAYS_HENCE 2
Attr:MAX_DIFF_SECS_AGO 3600
Attr:MAX_DIFF_SECS_HENCE 604800
Attr:MAX_EVENTS 256
Attr:MAX_TIMESTAMP_LOOKAHEAD 44
Attr:MUST_BREAK_AFTER
Attr:MUST_NOT_BREAK_AFTER
Attr:MUST_NOT_BREAK_BEFORE
Attr:SEGMENTATION indexing
Attr:SEGMENTATION-all full
Attr:SEGMENTATION-inner inner
Attr:SEGMENTATION-outer outer
Attr:SEGMENTATION-raw none
Attr:SEGMENTATION-standard standard
Attr:SHOULD_LINEMERGE False
Attr:TRANSFORMS Attr:TRUNCATE 10000
Attr:is_valid True
Attr:maxDist 100
Attr:sourcetype trade_entries-2

Note attributes including sourcetype.

View solution in original post

0 Karma

rroberts
Splunk Employee
Splunk Employee

Check the CLI test. From $SPLUNK_HOME/bin Check help for test... ./splunk test help ./splunk test sourcetype

Example:

./splunk test sourcetype /opt/tradelog/trade_entries.log

PROPERTIES OF /opt/log/tradelog/trade_entries.log
Attr:ANNOTATE_PUNCT True
Attr:BREAK_ONLY_BEFORE
Attr:BREAK_ONLY_BEFORE_DATE True
Attr:CHARSET UTF-8
Attr:DATETIME_CONFIG /etc/datetime.xml
Attr:HEADER_MODE
Attr:LEARN_SOURCETYPE true
Attr:LINE_BREAKER_LOOKBEHIND 100
Attr:MAX_DAYS_AGO 2000
Attr:MAX_DAYS_HENCE 2
Attr:MAX_DIFF_SECS_AGO 3600
Attr:MAX_DIFF_SECS_HENCE 604800
Attr:MAX_EVENTS 256
Attr:MAX_TIMESTAMP_LOOKAHEAD 44
Attr:MUST_BREAK_AFTER
Attr:MUST_NOT_BREAK_AFTER
Attr:MUST_NOT_BREAK_BEFORE
Attr:SEGMENTATION indexing
Attr:SEGMENTATION-all full
Attr:SEGMENTATION-inner inner
Attr:SEGMENTATION-outer outer
Attr:SEGMENTATION-raw none
Attr:SEGMENTATION-standard standard
Attr:SHOULD_LINEMERGE False
Attr:TRANSFORMS Attr:TRUNCATE 10000
Attr:is_valid True
Attr:maxDist 100
Attr:sourcetype trade_entries-2

Note attributes including sourcetype.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

Data Management Digest – May 2026

Welcome to the May 2026 edition of Data Management Digest!   As your trusted partner in data innovation, the ...