Basically, I want to have ONE log file populating TWO sourcetypes at the same time. Identical events in both. Eventually, I'll kill off the old sourcetype and only have the events going into the sourcetype with the new name.
I'm doing this because I want to check parity and catch bugs or other issues for the new sourcetype. What is the best approach for this?
So to clarify, you are indexing one log file, twice, as two different sourcetypes.
If you are indexing the same file twice, what kind of differences are you expecting to catch?
In the end, you just drop the monitor / input for the sourcetype you want to get rid of.