Getting Data In

How to add a new sourcetype to an existing index?

shrirangphadke
Path Finder

Hi,

Sorry if my question is repeated.

I have an index with sourcetype as 'firewall' and now I want to add one more sourcetype to the existing index called 'security'.

How do I achieve that? Please help.

Tags (2)
0 Karma

somesoni2
SplunkTrust
SplunkTrust

There is no index level configuration required for a new sourcetype. Just configure your sourcetype in props.conf on Heavy forwarder/Indexers and configure your data inputs to use the existing index and new sourcetype.

dineshraj
Explorer

Just add the new monitor and sourcetype in inputs.conf, it will starting showing the data.

If you want specific processing add configurations in props.conf for the sourcetype..

Get Updates on the Splunk Community!

What’s New in Splunk Cloud Platform 9.1.2308?

Hi Splunky people! We are excited to share the newest updates in Splunk Cloud Platform 9.1.2308! Analysts can ...

Index This | Why do they call it hyper text?

November 2023 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

State of Splunk Careers 2023: Career Resilience and the Continued Value of Splunk

For the past three years, Splunk has partnered with Enterprise Strategy Group to conduct a survey that gauges ...