Total noob here. I want to create a source type that is an aggregate of several source types. What I want to eventually end up with is the ability to easily apply several REPORT rules to a set of source types. Below is a mockup of roughly what I want functionality-wise in my props.conf:
[sourcetype1 sourcetype2 sourcetype3 sourcetype4]
REPORT-AAAAA = AAAAA
REPORT-BBBBB = BBBBB
REPORT-CCCCC = CCCCC
REPORT-DDDDD = DDDDD
Is something along these lines possible to do in Splunk? Thanks for any help
Depending on your sourcetypes this might take you a step closer: http://blogs.splunk.com/2014/07/31/quick-tip-wildcard-sourcetypes-in-props-conf/
Considering that's evaluating a regex you should be able to list your four sample sourcetypes separated by pipes as OR and be done.