Getting Data In

How to partition indexed logfiles into multiple sourcetype?

edgarrity
Path Finder

We need to index logfiles from our monitored devices which are partitioned into two segments.  The first segment is CSV.  The last segment are events.

 

col1,col2,col3,…,colN

col1,col2,col3,… ,colN

col1,col2,col3,… ,colN

.

.

.

event1

event2

event3

eventN

 

This data from the logfile needs to be sent to one index with a two sourcetypes.  Sourcetype_csv for the first segment in the logfile and sourcetype_events for the last segment in the logfile.  How do we structure the inputs.conf, props.conf, and transforms.conf for this?

 

We were thinking we could leverage filtering to take advantage that the events are all prefixed and postfixed with “***”.  However, there does not seem to be a way to have the one logfile type partitioned into more than one sourcetype.

Tags (1)
0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi @edgarrity,

if you can find a regex to identify logs of the dirst or of the second type, you have two solutions:

Ciao.

Giuseppe

View solution in original post

gcusello
SplunkTrust
SplunkTrust

Hi @edgarrity,

if you can find a regex to identify logs of the dirst or of the second type, you have two solutions:

Ciao.

Giuseppe

edgarrity
Path Finder

Thanks.

That worked.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...