Getting Data In

How does Splunk find sourcetypes?

aapittts
Path Finder

I have several instances of SplunkforBlueCoat and have recently run into a strange issue. Splunk cannot find the BlueCoat sourcetype. I haven't had this issue before and I've checked my props.conf & transforms.conf with correct ones and cannot find any differences. Can anyone point me in the right direction?

0 Karma

yannK
Splunk Employee
Splunk Employee

check the inputs.conf, this is where you specify which sourcetype to apply to which source.

0 Karma

aapittts
Path Finder

I'm not seeing where in the inputs.conf the source type is defined.

0 Karma

aapittts
Path Finder

should there be an inputs.conf in the default or local directories of Splunk for Blue Coat?

0 Karma
Get Updates on the Splunk Community!

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

See your relevant APM services, dashboards, and alerts in one place with the updated ...

As a Splunk Observability user, you have a lot of data you have to manage, prioritize, and troubleshoot on a ...

Index This | What goes away as soon as you talk about it?

May 2025 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with this month’s ...