All,
On the list of pretrained sourcetypes I see /var/log/messages as linux_messages_syslog (https://docs.splunk.com/Documentation/Splunk/7.0.3/Data/Listofpretrainedsourcetypes) but in Splunk for Nix I see them setting it as syslog.
What is the prefered sourcetype here? I guess I should point out that I am looking for ideal interoperability with Splunk ES and additional apps down the road.
You can use "linux_messages_syslog" if you are not using nix app.