My understanding is that this is now done via a splunk config file. How?
You could do this via a lookup table - http://docs.splunk.com/Documentation/Splunk/5.0/Knowledge/Aboutlookupsandfieldactions
or via a tag - http://docs.splunk.com/Documentation/Splunk/5.0/Knowledge/Abouttagsandaliases
You could do this via a lookup table - http://docs.splunk.com/Documentation/Splunk/5.0/Knowledge/Aboutlookupsandfieldactions
or via a tag - http://docs.splunk.com/Documentation/Splunk/5.0/Knowledge/Abouttagsandaliases