Getting Data In

is it safe for app-developers to use pulldown_type=true on their sourcetypes

sideview
SplunkTrust
SplunkTrust

props.conf has a boolean setting called "pulldown_type".

If you set it to true, then the name of your sourcetype will appear in the end-users' sourcetype dropdowns in manager.
For app developers, who are often defining their own custom sourcetypes as a part of their shipping app, this key is obviously quite nice for their end users.

In the documentation however, pulldown_type is listed under "internal fields", with a note saying "Not yours - do not set".

My question is -- is there some hidden pitfall to setting that key? Is that warning really warranted? If not I'm going to start setting it to true in all my apps that define one or more custom sourcetypes.

Tags (1)

dart
Splunk Employee
Splunk Employee

I'd set it to true, and also set the new description and category fields.

0 Karma

southeringtonp
Motivator

Interestingly enough, Splunk 4.3 sets this value when creating new sourcetypes as part of the initial setup 'Add data' screens and choosing "Set a new sourcetype". Certainly that would seem to imply that the warning isn't warranted, but it would be nice to see confirmation and some insight into the original reason for the warning.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Vibe-coding, AI, and Splunkcraft: Highlights from the .conf26 Builder Bar

If you stopped by the Builder Bar at .conf26, thank you! This year, we brought ...

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...