Getting Data In

How to assign a custom sourcetype for a data stream flowing via API calls?

olavo123
Explorer

I have data being streamed into Splunk using the Python SDK API call. Works perfectly fine using one of the built in sourcetypes: access-combined. But, now I wish to assign a custom sourcetype for the data coming via API calls.

How can I do this? I noticed that using props.conf requires you to specify an input source. Is there any other way to create this sourcetype.

Thanks

Olavo

woodcock
Esteemed Legend

You control the sourcetype so just set it to any string that you like when you setup your input (this will end up as a sourcetype=YourString configuration line inside the stanza related to your input inside of inputs.conf).

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...