Splunk Search

Fields for multiple sourcetype

vaibhavagg2006
Communicator

Hi,
I wanted to know what is the best technique used for creating fields for multiple sourcetypes.
For example if i have 4 sourcetype named
st1,st2,st3,st4
I want to extract a field which displays errros.
So shall I create duplicate fields for each sourcetype or there is some better method available.

Tags (1)
0 Karma

sdaniels
Splunk Employee
Splunk Employee

Yes, you will have separate fields extractions for each sourcetype. If st1, st2 etc are all the same format then you'd combine them into a single sourcetype.

You could define an eventtype to have a nice way to search across all of those sourcetypes for specific errors.

http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Defineeventtypes

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...