Hi Team,
I am trying to extract fields out of my log files. Even though the files are generated by the same source and system and exactly same columns, Splunk is classifying it them into multiple different sourcetypes. The challenge - I have to extract the same fields numerous times from each sourcetype.
Any idea why this behavior is happening?
Regards,
Varun Biswas
Assign a sourcetype yourself inside of inputs.conf
like this:
sourcetype=MySourcetype