Splunk Search

Single Input with multiple host and multiple Sourcetype

jackykitkit
New Member

I would like to know can I configure splunk to receive syslog in Single Input (UDP:514) with multiple host and multiple Sourcetype. If so, how can I do that?
Thanks

Tags (1)
0 Karma

mloven_splunk
Splunk Employee
Splunk Employee

Yep. You want to look at doing a host override and a sourcetype override. Well, several of each, probably.

These links should get you started:

http://answers.splunk.com/answers/12439/sourcetype-override

http://answers.splunk.com/answers/24769/host-override

0 Karma
Get Updates on the Splunk Community!

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...