Splunk Search

Log files are generated from the same source, system, and columns, but why is Splunk classifying them into multiple different sourcetypes?

varunbiswas
New Member

Hi Team,

I am trying to extract fields out of my log files. Even though the files are generated by the same source and system and exactly same columns, Splunk is classifying it them into multiple different sourcetypes. The challenge - I have to extract the same fields numerous times from each sourcetype.

Any idea why this behavior is happening?

Regards,
Varun Biswas

0 Karma

woodcock
Esteemed Legend

Assign a sourcetype yourself inside of inputs.conf like this:

sourcetype=MySourcetype
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...