Getting Data In

Is there a way in Splunk to ingest a zip file with multiple sourcetypes?

OMohi
Path Finder

Hi All:

I want to ingest a zip file that has multiple sourcetypes. Is there a mechanism on how to achieve it? Please let me know.

Thanks

0 Karma

grijhwani
Motivator

A variation of this question comes up periodically, and the basic answer is "no". A sourcetype is tied to the source in a one-to-many relationship. If your source is a set of zip files, then the sourcetype will apply to the zip files in their entirety, not their contents.

A possible solution is a triggered script, which unpacks the zip and allows you to then ingest the component files individually as defined sources in their own right.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...