Our server can input data into Splunk either via Syslog or Http Event Collector. In our Splunk application, we want the user to be able to specify which method they are using and then create a macro based on that information. This is to handle our legacy Splunk application that currently only uses syslog. With our next release we are adding Http Event Collector too.
We want to configure setup.xml for our application to define a macro based on user input.
A boolean input for "Use Syslog Data"
In macros.conf file:
[DiagnosticsDataSource(1)]
args = diagnosticsType
if "Use Syslog Data" = true
definition = sourcetype=syslog LocalityServer "$diagnosticsType$"
else
definition = sourcetype= "$diagnosticsType$"
Have you considered just OR'ing both options statically?
Great. I've converted the comment to an answer, feel free to mark this as accepted if you're happy.
Thanks. This works.