Skip to main content

sources

Creates, updates, deletes, gets or lists a sources resource.

Overview​

Namesources
TypeResource
Idsumologic.collectors.sources

Fields​

The following fields are returned by SELECT queries:

NameDatatypeDescription
idintegerUnique identifier of the Source.
namestringName of the Source.
host_namestringHost name assigned to data from this Source (the _sourceHost metadata field). (wire: hostName)
alivebooleanWhether the Source is alive.
automatic_date_parsingbooleanWhether timestamps are parsed automatically. (wire: automaticDateParsing)
categorystringSource category (the _sourceCategory metadata field).
content_typestringContent type of the data collected (used by some cloud Source types). (wire: contentType)
cutoff_relative_timestringRelative offset instead of cutoffTimestamp, for example -1h, -1d or -1w. (wire: cutoffRelativeTime)
cutoff_timestampinteger (int64)Only collect data more recent than this timestamp, in milliseconds since epoch. (wire: cutoffTimestamp)
default_date_formatsarrayDefault date formats used to parse timestamps. (wire: defaultDateFormats)
denylistarrayPath expressions to exclude from collection (file Sources).
descriptionstringDescription of the Source.
encodingstringCharacter encoding of the data (default UTF-8).
fieldsstringJSON map of key-value fields (metadata) applied to the Source. (opaque JSON object)
filtersarrayProcessing rules (Exclude, Include, Hash, Mask, Forward) applied to the Source.
force_time_zonebooleanWhen true, the timeZone is applied to all messages. (wire: forceTimeZone)
hash_algorithmstringHash algorithm used by Hash processing rules. (wire: hashAlgorithm)
intervalintegerCollection interval in milliseconds (metrics and script Sources).
manual_prefix_regexpstringRegular expression that marks the start of a message when useAutolineMatching is false. (wire: manualPrefixRegexp)
message_per_requestbooleanFor HTTP Sources, whether each request is a single message. (wire: messagePerRequest)
metricsarrayMetrics to collect (SystemStats Sources).
multiline_processing_enabledbooleanWhether multiline message processing is enabled. (wire: multilineProcessingEnabled)
path_expressionstringPath expression of the files to collect (file Sources). (wire: pathExpression)
source_typestringType of the Source, for example HTTP, LocalFile, RemoteFileV2, Syslog, SystemStats, Polling, Script, and the cloud-to-cloud types. (wire: sourceType)
statusstringSource status (cloud Sources). (opaque JSON object)
third_party_refstringCloud-to-cloud Source configuration. (opaque JSON object) (wire: thirdPartyRef)
time_zonestringTime zone applied to messages when forceTimeZone is true or the message has no time zone. (wire: timeZone)
urlstringUnique URL of an HTTP Source endpoint.
use_autoline_matchingbooleanWhether message boundaries are inferred automatically. (wire: useAutolineMatching)

Methods​

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
getselectcollector_id, source_id, regiondownloadGet information about a specified Source of a Collector. The response carries an ETag header, which must be supplied as If-Match on an update.
listselectcollector_id, regiondownloadGet information about all Sources of a specified Collector.
createinsertcollector_id, region, sourceCreate a new Source on a Collector. The request body is the Source definition wrapped in a source object; see the vendor documentation (Use JSON to Configure Sources) for the fields required by each sourceType.
updateupdatecollector_id, source_id, region, sourceif-_matchUpdate a Source. The Collector Management API requires the If-Match header to carry the ETag returned by a previous GET of the same Source; the request body is the full Source object wrapped in source.
deletedeletecollector_id, source_id, regionDelete the specified Source of a Collector.

Parameters​

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
collector_idstringUnique identifier of the Collector. (wire: collectorId)
regionstringSumo Logic deployment (au, ca, ch, de, eu, fed, in, jp, kr, us1, us2). Resolved from the SUMOLOGIC_ENVIRONMENT environment variable when it is set (x-stackQL-envVar, the same variable the Terraform provider reads); otherwise defaults to us2. A WHERE region = '...' value always takes precedence. (enum: [au, ca, ch, de, eu, fed, in, jp, kr, us1, us2], default: us2, x-stackQL-envVar: SUMOLOGIC_ENVIRONMENT)
source_idstringUnique identifier of the Source. (wire: sourceId)
downloadbooleanWhen true, the response is the JSON configuration of the Source(s), suitable for registering a new Collector or creating a new Source.
if-_matchstringThe ETag value returned in the response headers of a previous GET of this object. The Collector Management API requires it on updates. (wire: If-Match)

SELECT examples​

Get information about a specified Source of a Collector. The response carries an ETag header, which must be supplied as If-Match on an update.

SELECT
id,
name,
host_name,
alive,
automatic_date_parsing,
category,
content_type,
cutoff_relative_time,
cutoff_timestamp,
default_date_formats,
denylist,
description,
encoding,
fields,
filters,
force_time_zone,
hash_algorithm,
interval,
manual_prefix_regexp,
message_per_request,
metrics,
multiline_processing_enabled,
path_expression,
source_type,
status,
third_party_ref,
time_zone,
url,
use_autoline_matching
FROM sumologic.collectors.sources
WHERE collector_id = '{{ collector_id }}' -- required
AND source_id = '{{ source_id }}' -- required
AND region = '{{ region }}' -- required unless SUMOLOGIC_ENVIRONMENT is set
AND download = '{{ download }}'
;

INSERT examples​

Create a new Source on a Collector. The request body is the Source definition wrapped in a source object; see the vendor documentation (Use JSON to Configure Sources) for the fields required by each sourceType.

INSERT INTO sumologic.collectors.sources (
source,
collector_id,
region
)
SELECT
'{{ source }}' /* required */,
'{{ collector_id }}',
'{{ region }}'
RETURNING
source
;

UPDATE examples​

Update a Source. The Collector Management API requires the If-Match header to carry the ETag returned by a previous GET of the same Source; the request body is the full Source object wrapped in source.

UPDATE sumologic.collectors.sources
SET
source = '{{ source }}'
WHERE
collector_id = '{{ collector_id }}' --required
AND source_id = '{{ source_id }}' --required
AND region = '{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
AND source = '{{ source }}' --required
AND if-_match = '{{ if-_match}}'
RETURNING
source;

DELETE examples​

Delete the specified Source of a Collector.

DELETE FROM sumologic.collectors.sources
WHERE collector_id = '{{ collector_id }}' --required
AND source_id = '{{ source_id }}' --required
AND region = '{{ region }}' --required unless SUMOLOGIC_ENVIRONMENT is set
;