Add a custom data source
If you want to add a source that's not included in the list of known data sources, you can add a custom data source. To add a custom data source, complete the following steps:
- Select Configure then Data sources and then Data source management.
- Select Add data source configuration.
- From the drop-down list, select Add custom data source.
- Select the data source type. See Data source types for a description of the different data source types.
- Enter a nickname. The nickname is the display name for the data source, and it must be unique for each data source.
- Select the Category and Vendor.
- Turn on the toggle switch for the processing type you want to assign the data source to.
- Select whether or not to make the data source passive by turning the toggle switch on or off. A data source with a static data type, such as a CSV file upload, is a passive data source. Passive data sources don't have a reliable way of reporting a last detection date for when the assets were last active on the network. For passive data sources, Splunk Asset and Risk Intelligence doesn't label an asset as active if it was only discovered on that data source.
- (Optional) Select the toggle switch to turn on compliance window monitoring, and then enter a compliance window in seconds. The compliance window is the expected frequency that Splunk Asset and Risk Intelligence receives data from the source. If you turn on compliance window monitoring, you can see whether or not Splunk Asset and Risk Intelligence receives data from that source within the specified window. If you don't want to set a particular compliance window time, enter 0.
- Select Add.