We have a dozen logs to ingest into Splunk. The log data will be obtained using regular expressions. Based on local conventions, we'll be creating a dozen source types, each named for its corresponding log.
As it turns out, only two regular expressions are needed for the dozen logs, one regular expression for 4 of the logs, and the second regular expression for the other 8 logs.
I don't want to copy and paste the one regular expression into 4 of the source types and the other regular expression into the other 8 source types. Instead, I want to store the two regular expressions in Splunk one time each and then reference each of the two regular expressions from the 12 source types as appropriate.
Is there a way to store the regular expressions in Splunk one time each and then reference them from the 12 source types?