SourceTypes
Query the source type definitions in Splunk.
Columns
| Name | Type | Description |
| Name [KEY] | String | The name of the source type. |
| Id | String | The REST resource link for the source type. |
| UpdatedAt | Datetime | Datetime of the last update of the source type. |
| Author | String | The Splunk user that created the source type. |
| App | String | The Splunk app where the source type is shared. |
| CanChangePerms | Boolean | Indicates whether the user can change the permissions of the source type. |
| CanList | Boolean | Indicates whether the source type can be listed by the user. |
| CanShareApp | Boolean | Indicates whether the source type can be shared at the app level. |
| CanShareGlobal | Boolean | Indicates whether the source type can be shared globally. |
| CanShareUser | Boolean | Indicates whether the source type can be shared at the user level. |
| CanWrite | Boolean | Indicates whether the source type can be modified by the user. |
| Modifiable | Boolean | Indicates whether the source type can be modified. |
| Owner | String | The Splunk user that owns the source type. |
| ReadPermissions | String | Permissions to read this source type. |
| WritePermissions | String | Permissions to write to this source type. |
| Removable | Boolean | Indicates whether the source type can be removed. |
| Sharing | String | The source type sharing type. |
| Sourcetype | String | The source type name that this definition applies to. |
| Category | String | The category that the source type is grouped under in Splunk Web. |
| Description | String | Human-readable description of the source type. |
| PulldownType | Boolean | Indicates whether the source type is displayed in the source type pulldown menu in Splunk Web. |
| Priority | String | Specifies the precedence of the source type when multiple source types match. |
| IsValid | Boolean | Indicates whether the source type configuration is valid. |
| InvalidCause | String | The reason the source type configuration is invalid, when applicable. |
| Charset | String | The character set encoding used by the input data. |
| ShouldLinemerge | Boolean | Indicates whether Splunk software combines several lines of data into a single multiline event. |
| LineBreaker | String | A regular expression that determines how the raw text stream is broken into initial events. |
| LineBreakerLookbehind | Integer | The maximum number of characters to take into account when breaking events with LineBreaker. |
| Truncate | Integer | The maximum line length, in bytes. Lines longer than this are truncated. |
| BreakOnlyBefore | String | A regular expression. When set, Splunk software creates a new event only if it encounters a line that matches. |
| BreakOnlyBeforeDate | Boolean | Indicates whether to create a new event only if a new line with a date is encountered. |
| MustBreakAfter | String | A regular expression. When set, Splunk software breaks an event after the matching text. |
| MustNotBreakAfter | String | A regular expression. When set, Splunk software does not break an event after the matching text. |
| MustNotBreakBefore | String | A regular expression. When set, Splunk software does not break an event before the matching text. |
| MaxEvents | Integer | The maximum number of input lines to add to any single event. |
| MaxExpectedEventLines | String | The maximum number of lines expected in a single event. |
| EventBreaker | String | A regular expression that specifies the event boundary for the event breaker. |
| EventBreakerEnable | String | Indicates whether the event breaker is enabled for the source type. |
| Segmentation | String | The segmentation type used when indexing events of this source type. |
| SegmentationAll | String | The 'all' segmentation definition for this source type. |
| SegmentationInner | String | The 'inner' segmentation definition for this source type. |
| SegmentationOuter | String | The 'outer' segmentation definition for this source type. |
| SegmentationRaw | String | The 'raw' segmentation definition for this source type. |
| SegmentationStandard | String | The 'standard' segmentation definition for this source type. |
| TimeFormat | String | The strptime format string used to extract the timestamp from events. |
| TimePrefix | String | A regular expression that locates the timestamp within an event. |
| MaxTimestampLookahead | Integer | The number of characters into an event Splunk software scans for a timestamp. |
| DatetimeConfig | String | The file that specifies timestamp extraction rules for the source type. |
| TimestampFields | String | The list of fields used to construct a timestamp. |
| MaxDaysAgo | Integer | The maximum number of days in the past, from the current date, that an extracted date can be valid. |
| MaxDaysHence | Integer | The maximum number of days in the future, from the current date, that an extracted date can be valid. |
| MaxDiffSecsAgo | Integer | The number of seconds an event timestamp can lag behind the preceding event before being flagged. |
| MaxDiffSecsHence | Integer | The number of seconds an event timestamp can be ahead of the preceding event before being flagged. |
| DetermineTimestampDateWithSystemTime | String | Indicates whether to use the system time to determine the date component of a timestamp when it is missing. |
| AddExtraTimeFields | String | Indicates whether to write the date_* fields to the index for events of this source type. |
| KvMode | String | The mode used for automatic key-value field extraction at search time. |
| AutoKvJson | String | Indicates whether automatic JSON key-value extraction is enabled. |
| IndexedExtractions | String | The format of the file, used for index-time field extraction (for example, JSON, CSV, TSV). |
| Transforms | String | The index-time transforms applied to events of this source type. |
| MatchLimit | String | The maximum number of times a regular expression match is attempted during extraction. |
| DepthLimit | String | The maximum recursion depth allowed during regular expression matching. |
| FieldDelimiter | String | The delimiter used to separate fields in structured (for example, CSV) data. |
| HeaderFieldDelimiter | String | The delimiter used to separate header fields in structured data. |
| HeaderMode | String | Specifies how the header is detected in structured data. |
| JsonTrimBracesInArrayNames | String | Indicates whether braces are trimmed from array names during JSON extraction. |
| NoBinaryCheck | Boolean | Indicates whether Splunk software ingests files that appear to be binary. |
| CheckMethod | String | The method used to detect whether a file has already been indexed. |
| PrefixSourcetype | Boolean | Indicates whether the source type name is prefixed to automatically generated source type names. |
| MetricsProtocol | String | The protocol used to parse metrics data for this source type. |
| LbChunkBreakerTruncate | String | The maximum number of bytes a line breaker reads in a single chunk. |
| AnnotatePunct | Boolean | Indicates whether to create the punct field during indexing. |
| DetectTrailingNulls | String | Indicates how Splunk software handles trailing null characters in events. |
| LearnModel | Boolean | Indicates whether Splunk software learns a model for new source types. |
| LearnSourcetype | Boolean | Indicates whether Splunk software automatically generates new source types. |
| MaxDist | Integer | The maximum distance, used to determine how similar events must be to share a learned source type. |
| TermFrequencyWeightedDist | String | Indicates whether term-frequency weighting is used when computing source type similarity. |
| TrackPipelineLatency | String | Indicates whether pipeline latency tracking is enabled for this source type. |
| UnarchiveCmdStartMode | String | The start mode used for the unarchive command of this source type. |