Splunk Search

Fields for multiple sourcetype

vaibhavagg2006
Communicator

Hi,
I wanted to know what is the best technique used for creating fields for multiple sourcetypes.
For example if i have 4 sourcetype named
st1,st2,st3,st4
I want to extract a field which displays errros.
So shall I create duplicate fields for each sourcetype or there is some better method available.

Tags (1)
0 Karma

sdaniels
Splunk Employee
Splunk Employee

Yes, you will have separate fields extractions for each sourcetype. If st1, st2 etc are all the same format then you'd combine them into a single sourcetype.

You could define an eventtype to have a nice way to search across all of those sourcetypes for specific errors.

http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Defineeventtypes

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOC4Kafka - New Kafka Connector Powered by OpenTelemetry

The new SOC4Kafka connector, built on OpenTelemetry, enables the collection of Kafka messages and forwards ...

Event Series: Level up your SOC: Advancing with Splunk Enterprise Security

AI has fundamentally raised the stakes for security operations, and this three-part series is your guide to ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...