Knowledge Management

What is the purpose of the sourcetype "stash_new"?

lcavaliere_splu
Splunk Employee
Splunk Employee

What is the purpose of the sourcetype "stash_new" as opposed to the "stash sourcetype?

0 Karma

Amandeepsin
New Member

Splunk automatically give this sourcetype. It doesn't cost us license and mentioning this stash it knows that license should not used while indexing summary index

0 Karma

vishaltaneja070
Motivator

Basically it is used when you are doing summary indexing using collect command.
Data first get written to a stash_new file.
After that file processed based on sourcetype stash_new and stash.

lcavaliere_splu
Splunk Employee
Splunk Employee

When incoming summary data is being processed (e.g. from the collect command), the associated sourcetype is initially "stash_new". After the staging of this data is complete, it then is transformed to the sourcetype "stash".

Also of interest, this also means that any setting of TZ done under the "stash" sourcetype will get clobbered in that tranformation. This explains the workaround/solution provided in the following post:
https://answers.splunk.com/answers/717448/why-does-setting-a-tz-for-sourcetype-stash-not-tak.html?mi...

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...