Getting Data In

How to assign all sources the same sourcetype?

sgarvin55
Splunk Employee
Splunk Employee

I want to assign ALL sources the sourcetype my_logs_555, and then use the Priority parameter in props.conf to apply a different sourcetype to a few sources here and there.

What would the stanza be to assign all sources to the sourcetype my_logs_555?

Something like this?
[source::...]
sourcetype = my_logs_555

Would this stanza also work for UNC paths?

Tags (1)

MarioM
Motivator

yes source will work even with regex like this:

[source::....(?<!tar.)(gz|tgz)]
sourcetype=a_sourcetype
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!