my local splunk master having a ossim_alarms.log file my requirement is that file to apply a multiple souretype
 
					
				
		
 
		
		
		
		
		
	
			
		
		
			
					
		Hi zippyopsadmin,
what do you mean with multiple sourcetype?
if you want to assign to an event a sourcetype based on a part of the source or a regex from the log, it's possible to override a sourcetype following the instructions at https://docs.splunk.com/Documentation/Splunk/latest/Data/Advancedsourcetypeoverrides .
But put much attention to this idea because in Splunk every thing (fields, eventypes, etc...) is related to sourcetype, this means that in this case you have more work to do!
Why do you want to assign many sourcetypes to the same log?
Bye.
Giuseppe
