Hi,
I have some nicely defined logfiles, with all key-value pair entries. We'd like to create dynamic sourcetypes, based upon one of the values in the event. Is this possible?
Yes it is. See below link from Splunk Doc
http://docs.splunk.com/Documentation/Splunk/6.2.5/Data/Advancedsourcetypeoverrides
Yes, see this:
http://docs.splunk.com/Documentation/Splunk/6.3.3/Data/Advancedsourcetypeoverrides
Example 1 (static sourcetype name):
[set_sourcetype_my_log_for_some_hosts]
REGEX = :\d\d\s+(?:\d+\s+|(?:user|daemon|local.?)\.\w+\s+)*\[?(host1|host2|host3)[\w\.\-]*\]?\s
FORMAT = sourcetype::my_log
DEST_KEY = MetaData:Sourcetype
Example 2 (dynamic host name but you can apply the same logic to MetaData:Sourcetype):
[syslog-host]
REGEX = :\d\d\s+(?:\d+\s+|(?:user|daemon|local.?)\.\w+\s+)*\[?(\w[\w\.\-]{2,})\]?\s
FORMAT = host::$1
DEST_KEY = MetaData:Host