hi,
how to create an automatic sourcetype, which is not there in the splunk list ?
how we can define the regex so that automatically splunk identifies the sourcetype and index.
pls help
thanks
hi smolcj
since sourcetypes for log events are created at index time, you should have a look at docs about props and transforms for a start.
cheers,
MuS