Getting Data In

How to assign a custom sourcetype for a data stream flowing via API calls?


I have data being streamed into Splunk using the Python SDK API call. Works perfectly fine using one of the built in sourcetypes: access-combined. But, now I wish to assign a custom sourcetype for the data coming via API calls.

How can I do this? I noticed that using props.conf requires you to specify an input source. Is there any other way to create this sourcetype.



Esteemed Legend

You control the sourcetype so just set it to any string that you like when you setup your input (this will end up as a sourcetype=YourString configuration line inside the stanza related to your input inside of inputs.conf).

0 Karma
.conf21 CFS Extended through 5/20!

Don't miss your chance
to share your Splunk
wisdom in-person or
virtually at .conf21!

Call for Speakers has
been extended through
Thursday, 5/20!