Getting Data In

How to override sourcetype AND index assignment?

jamesvz84
Communicator

The following docs should how to override sourcetype: http://docs.splunk.com/Documentation/Splunk/6.2.5/Data/Advancedsourcetypeoverrides

A similar method is used to override index.

My question is, how do I override sourcetype AND index at parsing time?

0 Karma
1 Solution
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!