Looking for assistance with the proper format for sourcetype for sending data from AWS SQS is json format.
https://docs.splunk.com/Documentation/AddOns/released/AWS/SQS
I have tested sourcetype set to aws:sqs and json and the data in splunk looks the same. Should I actually set aws:json?
Hi @rhendle
You can use aws:sqs because as per App doc this is the default one in-app so I suggest to use the config which one is suggested by App doc.