Splunk Search

Calling different sourcetype stanza's in search-time field extraction defined in props.conf

yuwtennis
Communicator

Hi!

I would like to get help if following configuration is possible or not.

I already have 1000 of events as sourcetype A in index A.
However , I want to use different stanza in props.conf for different purpose
perhaps as sourcetype B overriding sourcetype A.

Is such thing possible?
Any help is appreciated!

Thanks,
Yu

Tags (2)
0 Karma

woodcock
Esteemed Legend

You can override the entire sourcetype or a subset of the events in the sourcetype. You can also rename the entire sourcetype or a subset of the events in the sourcetype. This is all well-documented:
http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Advancedsourcetypeoverrides

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting V2

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...