Splunk Search

Fields for multiple sourcetype

vaibhavagg2006
Communicator

Hi,
I wanted to know what is the best technique used for creating fields for multiple sourcetypes.
For example if i have 4 sourcetype named
st1,st2,st3,st4
I want to extract a field which displays errros.
So shall I create duplicate fields for each sourcetype or there is some better method available.

Tags (1)
0 Karma

sdaniels
Splunk Employee
Splunk Employee

Yes, you will have separate fields extractions for each sourcetype. If st1, st2 etc are all the same format then you'd combine them into a single sourcetype.

You could define an eventtype to have a nice way to search across all of those sourcetypes for specific errors.

http://docs.splunk.com/Documentation/Splunk/latest/Knowledge/Defineeventtypes

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...