my local splunk master having a ossim_alarms.log file my requirement is that file to apply a multiple souretype
Hi zippyopsadmin,
what do you mean with multiple sourcetype?
if you want to assign to an event a sourcetype based on a part of the source or a regex from the log, it's possible to override a sourcetype following the instructions at https://docs.splunk.com/Documentation/Splunk/latest/Data/Advancedsourcetypeoverrides .
But put much attention to this idea because in Splunk every thing (fields, eventypes, etc...) is related to sourcetype, this means that in this case you have more work to do!
Why do you want to assign many sourcetypes to the same log?
Bye.
Giuseppe