Splunk Search

How to merge two field as sourcetype?

rendie
Path Finder

Hi,

I wanna merge two fields into sourcetype as below:

props.conf

[source::/path/to/folder/*]
sourcetype = coalesce(field1,field2)

 

So, as result, I getting field sourcetype with the value "coalesce(field1,field2)". How to solve an issue?

Thanks.

Labels (2)
0 Karma
1 Solution

General_Talos
Path Finder

Try in props.conf

[source::/path/to/folder/*]
EVAL-sourcetype = coalesce(field1,field2)

View solution in original post

0 Karma

General_Talos
Path Finder

Try in props.conf

[source::/path/to/folder/*]
EVAL-sourcetype = coalesce(field1,field2)
0 Karma

rendie
Path Finder

Oh yeah, it works for me. Thank you

0 Karma
Get Updates on the Splunk Community!

Update Your SOAR Apps for Python 3.13: What Community Developers Need to Know

To Community SOAR App Developers - we're reaching out with an important update regarding Python 3.9's ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Automatic Discovery Part 2: Setup and Best Practices

In Part 1 of this series, we covered what Automatic Discovery is and why it’s critical for observability at ...