... was specific operator to recursively look in a path. Sourcetype is not path so it won't make sense to use
... there. If you're looking to use wildcard in sourcetype name, try something like this
Thanks for the info. I'm not looking for a wildcard but more could I replace in the props file, source:....pathtolog, with [sourcetype:dadslogs], and then the regex, date, and extractions would apply to all logs that come in with a sourcetype of dadslogs?
Sorry - I'm getting dumped into the Splunk world and having some difficulties.
If all the data that belongs to
[source::.../dads_logs/*.log] (within Splunk search
index=* source=*/dads_logs/*.log) a single sourcetype and that sourcetype is only associated with aforementioned source, then you can replace