This really should be two separate transforms.
Take a look at this thread:
http://answers.splunk.com/questions/6623/conditional-index-and-sourcetype-name-inputs-conf-by-file-n...
This really should be two separate transforms.
Take a look at this thread:
http://answers.splunk.com/questions/6623/conditional-index-and-sourcetype-name-inputs-conf-by-file-n...