Hi there, I am in the situation where a number of devices are forwarding to splunk on UDP:514. I can easily enough create new sourcetypes for them, however with one of these sourcetypes, namely my DHCP sourcetype, I need to be able to linemerge just this sourcetype and not the others. I was previously able to accomplish this by applying this in props.conf:
[source::UDP:514]
SHOULD_LINEMERGE = True
BREAK_ONLY_BEFORE = notification
But of course, that line-merges all the other sourcetypes in UDP:514 as well.
Is there a way to line merge only a specific extracted sourcetype and not blanket apply it to the entire source input?
First off, read this: http://www.georgestarcher.com/splunk-success-with-syslog/
You can specify props.conf settings on a per-sourcetype basis - I'd even say that's the most common approach.
[your_sourcetype]
SHOULD_LINEMERGE = True