Getting Data In

How to assign all sources the same sourcetype?

Splunk Employee
Splunk Employee

I want to assign ALL sources the sourcetype my_logs_555, and then use the Priority parameter in props.conf to apply a different sourcetype to a few sources here and there.

What would the stanza be to assign all sources to the sourcetype my_logs_555?

Something like this?
sourcetype = my_logs_555

Would this stanza also work for UNC paths?

Tags (1)


yes source will work even with regex like this:

Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!