Splunk Search

HTTP Event Collector: automatic sourcetype detection

fiveturns
Engager

When using the HTTP Event Collector, is automatic sourcetype detection possible?

Every event at the moment appears to be getting "httpevent" as the source type. even though I'm not explicitly setting that sourcetype anywhere.

Has anybody managed to get the automatic detection working? Does anybody know if it's supported?

Tags (1)

hunters_splunk
Splunk Employee
Splunk Employee

Hi Fiveturns,

Yes, you can customize the sourcetype for HEC events. Please follow the instructions in the documentation here:
http://docs.splunk.com/Documentation/Splunk/6.6.0/Data/UsetheHTTPEventCollector#Configure_HTTP_Event...

Hope this helps.
Thanks!
Hunter

jpbaker22
Engager

I downvoted this post because did not address question

0 Karma

fiveturns
Engager

Hi Hunter,

The problem is I wanted splunk to perform auto source type detection based on the message. I know how to explicitly set the source type if I wanted to, and that seems to be what that article describes.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

How Edge Processor's Durable Queue Works

Edge Processor sits in one of the most consequential places in any Splunk pipeline: between your data sources ...