I'm setting up the rubrik app,
(https://github.com/rubrikinc/rubrik-addon-for-splunk/blob/master/docs/quick-start.md)
and it's assuming I've got sourcetypes of rubrik (sourcetype="rubrik:eventfeed") coming in.
I do have logs coming from our rubrik cluster but they are not showing up as that.
Do I need to change something on the clusters, Splunk or edit the instructions?
Sorry, I'm a Splunk noob.
You can either edit the app and change all the places that say sourcetype="rubrik:eventfeed"
OR you can CLONE_SOURCETYPE
in transforms.conf