Getting Data In

Setting sourcetype based on source with wildcards via web console?

cmeyers
Explorer

Hello all,
I am looking to set the sourcetype of my logs based of the logs' source. I know how to do this by modifying the .conf file, but I need to know how to do this from the web console. I know I can set the sourcetype from the monitoring directories, but it won't accept wildcards. Essentially want to get the example below, but via the web console.

[source::/file/archive/*BSM*]
sourcetype = solaris_bsm

Do I have to monitor the directory with a white/black list and then set the sourcetype? The directory I am monitoring will have several different desired sourcetypes in it. Will I have to, for each sourcetype in the directory, have its own data input configured to monitor the directory with the desired white/blacklist regex?
Thanks in advance for the help!

0 Karma

woodcock
Esteemed Legend

You can edit the configuration files somewhere else and then deploy then via app (Deployment Server or Search Head admin GUI).

0 Karma

cmeyers
Explorer

Update:
Set up the directory to be monitored with a whitelist for files that fall under a specific sourcetype. Worked perfectly, with the assuming I can just set up several monitors on the same dir, with a whitelist of for files. That was not the case. Can only have one directory monitor set up.

0 Karma

somesoni2
Revered Legend

I don't think the Index-time override of source can be done from the Splunk Web UI. You would need to use conf file methods. To override sourcetype based on source values (like in the question), you need to update props.conf on the forwarder (see this). I

0 Karma

cmeyers
Explorer

That is how I have done it in the past, by just updating the props.conf. With my company's new structure, we don't have write access to the conf files and need to do everything with the web console. I was just hoping there was a way to do it without having to access the conf files.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...