sources
Creates, updates, deletes, gets or lists a sources resource.
Overview​
| Name | sources |
| Type | Resource |
| Id | sumologic.collectors.sources |
Fields​
The following fields are returned by SELECT queries:
- get
- list
| Name | Datatype | Description |
|---|---|---|
id | integer | Unique identifier of the Source. |
name | string | Name of the Source. |
host_name | string | Host name assigned to data from this Source (the _sourceHost metadata field). (wire: hostName) |
alive | boolean | Whether the Source is alive. |
automatic_date_parsing | boolean | Whether timestamps are parsed automatically. (wire: automaticDateParsing) |
category | string | Source category (the _sourceCategory metadata field). |
content_type | string | Content type of the data collected (used by some cloud Source types). (wire: contentType) |
cutoff_relative_time | string | Relative offset instead of cutoffTimestamp, for example -1h, -1d or -1w. (wire: cutoffRelativeTime) |
cutoff_timestamp | integer (int64) | Only collect data more recent than this timestamp, in milliseconds since epoch. (wire: cutoffTimestamp) |
default_date_formats | array | Default date formats used to parse timestamps. (wire: defaultDateFormats) |
denylist | array | Path expressions to exclude from collection (file Sources). |
description | string | Description of the Source. |
encoding | string | Character encoding of the data (default UTF-8). |
fields | string | JSON map of key-value fields (metadata) applied to the Source. (opaque JSON object) |
filters | array | Processing rules (Exclude, Include, Hash, Mask, Forward) applied to the Source. |
force_time_zone | boolean | When true, the timeZone is applied to all messages. (wire: forceTimeZone) |
hash_algorithm | string | Hash algorithm used by Hash processing rules. (wire: hashAlgorithm) |
interval | integer | Collection interval in milliseconds (metrics and script Sources). |
manual_prefix_regexp | string | Regular expression that marks the start of a message when useAutolineMatching is false. (wire: manualPrefixRegexp) |
message_per_request | boolean | For HTTP Sources, whether each request is a single message. (wire: messagePerRequest) |
metrics | array | Metrics to collect (SystemStats Sources). |
multiline_processing_enabled | boolean | Whether multiline message processing is enabled. (wire: multilineProcessingEnabled) |
path_expression | string | Path expression of the files to collect (file Sources). (wire: pathExpression) |
source_type | string | Type of the Source, for example HTTP, LocalFile, RemoteFileV2, Syslog, SystemStats, Polling, Script, and the cloud-to-cloud types. (wire: sourceType) |
status | string | Source status (cloud Sources). (opaque JSON object) |
third_party_ref | string | Cloud-to-cloud Source configuration. (opaque JSON object) (wire: thirdPartyRef) |
time_zone | string | Time zone applied to messages when forceTimeZone is true or the message has no time zone. (wire: timeZone) |
url | string | Unique URL of an HTTP Source endpoint. |
use_autoline_matching | boolean | Whether message boundaries are inferred automatically. (wire: useAutolineMatching) |
| Name | Datatype | Description |
|---|---|---|
id | integer | Unique identifier of the Source. |
name | string | Name of the Source. |
host_name | string | Host name assigned to data from this Source (the _sourceHost metadata field). (wire: hostName) |
alive | boolean | Whether the Source is alive. |
automatic_date_parsing | boolean | Whether timestamps are parsed automatically. (wire: automaticDateParsing) |
category | string | Source category (the _sourceCategory metadata field). |
content_type | string | Content type of the data collected (used by some cloud Source types). (wire: contentType) |
cutoff_relative_time | string | Relative offset instead of cutoffTimestamp, for example -1h, -1d or -1w. (wire: cutoffRelativeTime) |
cutoff_timestamp | integer (int64) | Only collect data more recent than this timestamp, in milliseconds since epoch. (wire: cutoffTimestamp) |
default_date_formats | array | Default date formats used to parse timestamps. (wire: defaultDateFormats) |
denylist | array | Path expressions to exclude from collection (file Sources). |
description | string | Description of the Source. |
encoding | string | Character encoding of the data (default UTF-8). |
fields | string | JSON map of key-value fields (metadata) applied to the Source. (opaque JSON object) |
filters | array | Processing rules (Exclude, Include, Hash, Mask, Forward) applied to the Source. |
force_time_zone | boolean | When true, the timeZone is applied to all messages. (wire: forceTimeZone) |
hash_algorithm | string | Hash algorithm used by Hash processing rules. (wire: hashAlgorithm) |
interval | integer | Collection interval in milliseconds (metrics and script Sources). |
manual_prefix_regexp | string | Regular expression that marks the start of a message when useAutolineMatching is false. (wire: manualPrefixRegexp) |
message_per_request | boolean | For HTTP Sources, whether each request is a single message. (wire: messagePerRequest) |
metrics | array | Metrics to collect (SystemStats Sources). |
multiline_processing_enabled | boolean | Whether multiline message processing is enabled. (wire: multilineProcessingEnabled) |
path_expression | string | Path expression of the files to collect (file Sources). (wire: pathExpression) |
source_type | string | Type of the Source, for example HTTP, LocalFile, RemoteFileV2, Syslog, SystemStats, Polling, Script, and the cloud-to-cloud types. (wire: sourceType) |
status | string | Source status (cloud Sources). (opaque JSON object) |
third_party_ref | string | Cloud-to-cloud Source configuration. (opaque JSON object) (wire: thirdPartyRef) |
time_zone | string | Time zone applied to messages when forceTimeZone is true or the message has no time zone. (wire: timeZone) |
url | string | Unique URL of an HTTP Source endpoint. |
use_autoline_matching | boolean | Whether message boundaries are inferred automatically. (wire: useAutolineMatching) |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | collector_id, source_id, region | download | Get information about a specified Source of a Collector. The response carries an ETag header, which must be supplied as If-Match on an update. |
list | select | collector_id, region | download | Get information about all Sources of a specified Collector. |
create | insert | collector_id, region, source | Create a new Source on a Collector. The request body is the Source definition wrapped in a source object; see the vendor documentation (Use JSON to Configure Sources) for the fields required by each sourceType. | |
update | update | collector_id, source_id, region, source | if-_match | Update a Source. The Collector Management API requires the If-Match header to carry the ETag returned by a previous GET of the same Source; the request body is the full Source object wrapped in source. |
delete | delete | collector_id, source_id, region | Delete the specified Source of a Collector. |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
collector_id | string | Unique identifier of the Collector. (wire: collectorId) |
region | string | Sumo Logic deployment (au, ca, ch, de, eu, fed, in, jp, kr, us1, us2). Resolved from the SUMOLOGIC_ENVIRONMENT environment variable when it is set (x-stackQL-envVar, the same variable the Terraform provider reads); otherwise defaults to us2. A WHERE region = '...' value always takes precedence. (enum: [au, ca, ch, de, eu, fed, in, jp, kr, us1, us2], default: us2, x-stackQL-envVar: SUMOLOGIC_ENVIRONMENT) |
source_id | string | Unique identifier of the Source. (wire: sourceId) |
download | boolean | When true, the response is the JSON configuration of the Source(s), suitable for registering a new Collector or creating a new Source. |
if-_match | string | The ETag value returned in the response headers of a previous GET of this object. The Collector Management API requires it on updates. (wire: If-Match) |
SELECT examples​
- get
- list
Get information about a specified Source of a Collector. The response carries an ETag header, which must be supplied as If-Match on an update.
SELECT
id,
name,
host_name,
alive,
automatic_date_parsing,
category,
content_type,
cutoff_relative_time,
cutoff_timestamp,
default_date_formats,
denylist,
description,
encoding,
fields,
filters,
force_time_zone,
hash_algorithm,
interval,
manual_prefix_regexp,
message_per_request,
metrics,
multiline_processing_enabled,
path_expression,
source_type,
status,
third_party_ref,
time_zone,
url,
use_autoline_matching
FROM sumologic.collectors.sources
WHERE collector_id = '{{ collector_id }}' -- required
AND source_id = '{{ source_id }}' -- required
AND region = '{{ region }}' -- required unless SUMOLOGIC_ENVIRONMENT is set
AND download = '{{ download }}'
;
Get information about all Sources of a specified Collector.
SELECT
id,
name,
host_name,
alive,
automatic_date_parsing,
category,
content_type,
cutoff_relative_time,
cutoff_timestamp,
default_date_formats,
denylist,
description,
encoding,
fields,
filters,
force_time_zone,
hash_algorithm,
interval,
manual_prefix_regexp,
message_per_request,
metrics,
multiline_processing_enabled,
path_expression,
source_type,
status,
third_party_ref,
time_zone,
url,
use_autoline_matching
FROM sumologic.collectors.sources
WHERE collector_id = '{{ collector_id }}' -- required
AND region = '{{ region }}' -- required unless SUMOLOGIC_ENVIRONMENT is set
AND download = '{{ download }}'
;
INSERT examples​
- create
- Manifest
Create a new Source on a Collector. The request body is the Source definition wrapped in a source object; see the vendor documentation (Use JSON to Configure Sources) for the fields required by each sourceType.
INSERT INTO sumologic.collectors.sources (
source,
collector_id,
region
)
SELECT
'{{ source }}' /* required */,
'{{ collector_id }}',
'{{ region }}'
RETURNING
source
;
# Description fields are for documentation purposes
- name: sources
props:
- name: collector_id
value: "{{ collector_id }}"
description: Required parameter for the sources resource.
- name: region
value: "{{ region }}"
description: Required parameter for the sources resource.
- name: source
description: |
Source object. The set of properties depends on the sourceType; the properties listed here are the common ones.
value:
id: {{ id }}
name: "{{ name }}"
description: "{{ description }}"
category: "{{ category }}"
hostName: "{{ hostName }}"
sourceType: "{{ sourceType }}"
contentType: "{{ contentType }}"
alive: {{ alive }}
url: "{{ url }}"
encoding: "{{ encoding }}"
timeZone: "{{ timeZone }}"
forceTimeZone: {{ forceTimeZone }}
automaticDateParsing: {{ automaticDateParsing }}
multilineProcessingEnabled: {{ multilineProcessingEnabled }}
useAutolineMatching: {{ useAutolineMatching }}
manualPrefixRegexp: "{{ manualPrefixRegexp }}"
messagePerRequest: {{ messagePerRequest }}
defaultDateFormats:
- "{{ defaultDateFormats }}"
pathExpression: "{{ pathExpression }}"
denylist:
- "{{ denylist }}"
filters:
- filterType: "{{ filterType }}"
name: "{{ name }}"
regexp: "{{ regexp }}"
mask: "{{ mask }}"
fields: "{{ fields }}"
cutoffTimestamp: {{ cutoffTimestamp }}
cutoffRelativeTime: "{{ cutoffRelativeTime }}"
hashAlgorithm: "{{ hashAlgorithm }}"
interval: {{ interval }}
metrics:
- "{{ metrics }}"
thirdPartyRef: "{{ thirdPartyRef }}"
status: "{{ status }}"
UPDATE examples​
- update
Update a Source. The Collector Management API requires the If-Match header to carry the ETag returned by a previous GET of the same Source; the request body is the full Source object wrapped in source.
UPDATE sumologic.collectors.sources
SET
source = '{{ source }}'
WHERE
collector_id = '{{ collector_id }}' --required
AND source_id = '{{ source_id }}' --required
AND region = '{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
AND source = '{{ source }}' --required
AND if-_match = '{{ if-_match}}'
RETURNING
source;
DELETE examples​
- delete
Delete the specified Source of a Collector.
DELETE FROM sumologic.collectors.sources
WHERE collector_id = '{{ collector_id }}' --required
AND source_id = '{{ source_id }}' --required
AND region = '{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
;