This is not current Splunk documentation.
Splunk 3.4.2 is the latest version. Only use this page with older Splunk 2.0.x.
Splunk 3.4.2 is the latest version. Only use this page with older Splunk 2.0.x.
Splunk User Manual (Splunk v2.0)
Sources, Source Types and Hosts
Source
A source is a file, stream, or other data input from which Splunk indexes events. The value of source is usually some combination of pathname, filename, and extension such as /archive/server1/var/log/ or /var/log/messages. Files uploaded through Splunk's browser interface get the pathname of the directory monitor's sinkhole directory, so they'll look something like /opt/splunk/var/spool/splunk/file.ext.
No comments have been submitted.