Hi,
I have configured my props.conf and mentioned the "sourcetype" but later I dont see that sourcetype listed in the list while adding the data manually through manager-->datainput-->etc
I want to write/make changes in my configuration file so that whaterver the sourcetype I will define here would be listed in the SPLUNK while adding the data manually
You just need to add:
pulldown_type = true
to your props.conf config for the sourcetype.
You just need to add:
pulldown_type = true
to your props.conf config for the sourcetype.
Don't worry, If gkanapathy says so, just do it. 🙂
Can you please let me know any other alternative If i dont set this value in props.conf as per Spulnk Document ?
That is true. But the docs for props.conf say;
# NOT YOURS. DO NOT SET.
If you're saying that you'd like to define a sourcetype at the input level, that is certainly possible.
from inputs.conf.spec
sourcetype = <string>
* Sets the sourcetype key/field for events from this input.
* Primarily used to explicitly declare the source type for this data, as opposed
to allowing it to be determined via automated methods. This is typically
important both for searchability and for applying the relevant configuration for this
type of data during parsing and indexing.
* Detail: Sets the sourcetype key's initial value. The key is used during
parsing/indexing, in particular to set the source type field during
indexing. It is also the source type field used at search time.
* As a convenience, the chosen string is prepended with 'sourcetype::'.
* WARNING: Do not quote the <string> value: sourcetype=foo, not sourcetype="foo".
* If unset, Splunk picks a source type based on various aspects of the data.
There is no hard-coded default.
I am not entirely sure what your asking, but if you tell splunk via an input stanza to monitor a particular file/directory, and you specify a sourcetype, any data handled by that input stanza will have the specified sourcetype assigned to it's metadata.
I would explain you rather . When we try to import data manually through the Splunk GUI, we can provide sourcetype either by "Automatic","Manuall" or by "From List" options, I want to configure my splunk so that whatever source type I will define in props.conf file will be shown when I would selecet "From List" Option.
Please let me know if it is still unclear to you