Splunk Search

Can splunk index same data into one index but different sourcetypes??

Path Finder


I have to index a log file in linux server in to one index but need to have two different sourcetype. Is it possible??

I tried but when compare 

index = audit_idx sourcetype = linux_audit and index =audit_idx sourcetype = linux_audit_mll , results are not same there are few logs missing in each.

Want to know why its happening.

Thanks in advance..


Labels (1)
Tags (3)



you can use CLONE_SOURCETYPE to clone same event to the different sourcetype. You should remember that  it duplicates your license usage!


r. Ismo

0 Karma
Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...