I have data being streamed into Splunk using the Python SDK API call. Works perfectly fine using one of the built in sourcetypes: access-combined. But, now I wish to assign a custom sourcetype for the data coming via API calls.
How can I do this? I noticed that using props.conf requires you to specify an input source. Is there any other way to create this sourcetype.
You control the sourcetype so just set it to any string that you like when you setup your input (this will end up as a sourcetype=YourString configuration line inside the stanza related to your input inside of inputs.conf).