November 2018
Beginner
298 pages
7h 51m
English
The naming of custom source types should really reflect the source of the data, including (as applicable) the vendor, device type, app, and the type of data being indexed. Source type elements can be separated by underscores or colons, as exemplified by a couple of Splunk-provided source types and some variations; I personally like using colons between the elements:
vendor:product:typecisco:asawebsphere_corewebsphere:app:coredb2:diag or ibm:db2:diag
Read now
Unlock full access