Splunk 6.3
I am looking at the feature host_segment=x in inputs.conf. And wondering if there is a similar feature for source type?
For example, I have a directory of logs on the network for a series of servers that look like this
/NFS/mounts/Servername/sourcetype/thefiles.txt
I'd like to just set this, but that doesn't seem to work. Any trick to this? Or work around?
[monitor:////nfs/mounts/*/*/*]
host_segment=3
sourcetype_segment=4
disable=0
No, this doesnt exists. You could set a sourcetype based on the source of the file in transforms.conf, upstream at indextime or HF layer.