Getting Data In

inputs..conf and sourcetypes - Can't override the sourcetype

robsenk
Engager

We have the need to set a high level sourcetype in the inputs.conf to one sourcetype and override some of those sources using the prop.conf and provide a more meaningful sourcetype. This didn't work however, when I removed the sourcetype from the inputs.conf the props.conf went ahead and overrode the the automatic designation splunk assigned as expected.

The goal is to set all data to one sourcetype with inputs.conf and override sourcetypes for selected files with a specific info in the props.conf.

Note that we are indexing archive files directly that have several levels.

Should this be possible?

Splunk 5.0.4 build 172409.

0 Karma

rakesh_498115
Motivator

Hi robsenk..

if you wish to change to change all the sourcetypes to a common sourcetype. you can use the rename property in props.conf

[sourcetype1]
rename = CommonSourcetype

[sourcetype2]
rename = CommonSourcetype

[sourcetype3]
rename = CommonSourcetype

Hope this helps !!

0 Karma

robsenk
Engager

Thanks for the comment. I'm actually trying to change from a common sourcetype assigned in inputs to a sourcetype defined in the props.conf. It will not override the sourcetype defined in inputs.conf.

The reason we are assigning a common type in inputs.conf is because the auto assignment for sourcetype feature goes wild on our dataset.

0 Karma

walterk82
Path Finder

Did you resolve this question?

0 Karma
Get Updates on the Splunk Community!

Exporting Splunk Apps

Join us on Monday, October 21 at 11 am PT | 2 pm ET!With the app export functionality, app developers and ...

Cisco Use Cases, ITSI Best Practices, and More New Articles from Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Build Your First SPL2 App!

Watch the recording now!.Do you want to SPL™, too? SPL2, Splunk's next-generation data search and preparation ...