I've got Splunk configured to assign some custom sourcetypes to files when they're uploaded automatically from a watch directory. Some users would prefer to upload files by hand using the Splunk GUI and I want to make sure that they assign the correct sourcetype. They can do so by selecting "manual" for the sourcetype and then typing in the correct value. Unfortunately, this makes it easy to make a mistake.
Is it possible to customize the list of sourcetypes in the 'automatic' list shown in the Splunk Web GUI? I've googled a bit and looked around in the manuals but didn't follow if this is possible or not.
Thanks for any help.
Here's another question/answer that I think has the answer you're looking for:
http://answers.splunk.com/questions/7634/how-do-you-add-sourcetypes-to-the-pre-defined-sourcetypes
Here's another question/answer that I think has the answer you're looking for:
http://answers.splunk.com/questions/7634/how-do-you-add-sourcetypes-to-the-pre-defined-sourcetypes
Excellent. glad i could help.
Thanks very much, that's as easy as I'd hoped. Apologies for not finding this in the documentation myself. I'd already customized props.conf to understand the sourcetype, but didn't now about the [yoursourcetypehere] stanza.