Topics

| pdf version

How Splunk Works


Splunk > The IT Search Company

  • Search and navigate IT data from applications, servers and network devices in real-time.
  • Download Splunk

Localized Splunk documentation

Looking for Splunk documentation in other languages?

Create an alias for a source type

This documentation does not apply to the most recent version of Splunk.

This documentation applies to the following versions of Splunk: 3.2 , 3.2.1 , 3.2.2 , 3.2.3 , 3.2.4 , 3.2.5 , 3.2.6

Create an alias for a source type

Use these instructions to create an alias for one of Splunk's automatically assigned sourcetype= names. Source type aliases make it easier for users to search and navigate Splunk Web.


Aliasing doesn't actually change the sourcetype= value that is stored in Splunk's index, so source type aliases can't be used to set custom indexing properties or extracted field rules. If you're trying to ensure that custom properties or fields apply to events, you'll need to set sourcetype for an input, set sourcetype for a source, or train Splunk on a sourcetype.


via Splunk Web

By clicking on the drop down arrow next to any source type in Splunk Web's search results, you can create a source type alias:


Image:30_admin10_aliassourcetype-edit.jpg


Simply enter the new source type alias in the pop-up window:


Image:30_admin10_aliassourcetype-alias.jpg


Note: If you're not seeing source type under your results you may have hidden the source type field via the fields menu.

Revision: 207 | Contact | Privacy Policy | Terms of Use | Community content licensed under Creative Commons