Splunk Search

Multiple sourcetypes per source

Samslara
Explorer

Hi,
I have a novice question, but is it possible to have more than one sourcetype for a given source?

0 Karma

hjwang
Contributor

Sure.

In props.conf
[source::<your source name>]
TRANSFORMS-XXX = AAA
TRANSFORMS-YYY = BBB
...

In transforms.conf
[AAA]
REGEX = <Extract a trait in your log like host IP or something else>
DEST_KEY = MetaData:Sourcetype
FORMAT = sourcetype::<your sourcetype name>
[BBB]
...
Get Updates on the Splunk Community!

Your Guide to SPL2 at .conf24!

So, you’re headed to .conf24? You’re in for a good time. Las Vegas weather is just *chef’s kiss* beautiful in ...

Get ready to show some Splunk Certification swagger at .conf24!

Dive into the deep end of data by earning a Splunk Certification at .conf24. We're enticing you again this ...

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Now On-Demand Join us to learn more about how you can leverage Service Level Objectives (SLOs) and the new ...