Getting Data In

configuring props.conf

Contributor

Hi,

I have configured my props.conf and mentioned the "sourcetype" but later I dont see that sourcetype listed in the list while adding the data manually through manager-->datainput-->etc

I want to write/make changes in my configuration file so that whaterver the sourcetype I will define here would be listed in the SPLUNK while adding the data manually

Tags (2)
0 Karma
1 Solution

Splunk Employee
Splunk Employee

You just need to add:

pulldown_type = true

to your props.conf config for the sourcetype.

View solution in original post

Splunk Employee
Splunk Employee

You just need to add:

pulldown_type = true

to your props.conf config for the sourcetype.

View solution in original post

Ultra Champion

Don't worry, If gkanapathy says so, just do it. 🙂

0 Karma

Contributor

Can you please let me know any other alternative If i dont set this value in props.conf as per Spulnk Document ?

0 Karma

Ultra Champion

That is true. But the docs for props.conf say;

# NOT YOURS. DO NOT SET.

0 Karma

Splunk Employee
Splunk Employee

If you're saying that you'd like to define a sourcetype at the input level, that is certainly possible.

from inputs.conf.spec

sourcetype = <string>
* Sets the sourcetype key/field for events from this input.
* Primarily used to explicitly declare the source type for this data, as opposed
  to allowing it to be determined via automated methods.  This is typically
  important both for searchability and for applying the relevant configuration for this
  type of data during parsing and indexing.
* Detail: Sets the sourcetype key's initial value. The key is used during
  parsing/indexing, in particular to set the source type field during
  indexing. It is also the source type field used at search time.
* As a convenience, the chosen string is prepended with 'sourcetype::'.
* WARNING: Do not quote the <string> value: sourcetype=foo, not sourcetype="foo".
* If unset, Splunk picks a source type based on various aspects of the data.
  There is no hard-coded default.

I am not entirely sure what your asking, but if you tell splunk via an input stanza to monitor a particular file/directory, and you specify a sourcetype, any data handled by that input stanza will have the specified sourcetype assigned to it's metadata.

0 Karma

Contributor

I would explain you rather . When we try to import data manually through the Splunk GUI, we can provide sourcetype either by "Automatic","Manuall" or by "From List" options, I want to configure my splunk so that whatever source type I will define in props.conf file will be shown when I would selecet "From List" Option.
Please let me know if it is still unclear to you

0 Karma