Splunk Enterprise

How to configure Advance section in Source Types?

kyoshiike
Explorer

Folks,

Does anyone know when we configure advanced secution in Source Type (Settings>SourceTypes and Edit), where is original configuration file where the advanced view shows?

I choose "linux_secure" source type and check advanced tab. I saw "src" and "src_ip" in search result for my data that used this source type. However I could't find any settings for these fields. So I though there were missing configurations in this tab and I wanted to know source configuration files for each source types.

Please someone share your knowledge.

Labels (2)
0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Thanks for the Memories! Splunk University, .conf24, and Community Connections

Thank you to everyone in the Splunk Community who joined us for .conf24 – starting with Splunk University and ...

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...