Getting Data In

How does Splunk find sourcetypes?

aapittts
Path Finder

I have several instances of SplunkforBlueCoat and have recently run into a strange issue. Splunk cannot find the BlueCoat sourcetype. I haven't had this issue before and I've checked my props.conf & transforms.conf with correct ones and cannot find any differences. Can anyone point me in the right direction?

0 Karma

yannK
Splunk Employee
Splunk Employee

check the inputs.conf, this is where you specify which sourcetype to apply to which source.

0 Karma

aapittts
Path Finder

I'm not seeing where in the inputs.conf the source type is defined.

0 Karma

aapittts
Path Finder

should there be an inputs.conf in the default or local directories of Splunk for Blue Coat?

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...