I'm setting up the rubrik app,
and it's assuming I've got sourcetypes of rubrik (sourcetype="rubrik:eventfeed") coming in.
I do have logs coming from our rubrik cluster but they are not showing up as that.
Do I need to change something on the clusters, Splunk or edit the instructions?
Sorry, I'm a Splunk noob.
You can either edit the app and change all the places that say sourcetype="rubrik:eventfeed" OR you can CLONE_SOURCETYPE in transforms.conf