Hi,
I've installed the TrackMe app in my Splunk Cloud environment. It's automatically discovered my environment, including indexes and sourcetypes. I want to monitor most sources by index, not sourcetype. I've configured the index to be monitored, but all the additional sourcetypes for that index still remain. Do I need to click on each of these and delete them? Is there another way to do this? It's a fair amount of sourcetypes.
Received answer on Slack. Use elastic sources.