Repository for sourcetype configuration for common log formats?


Is there a repository for common log formats? I have Tomcat boot.log that is not line breaking correctly, most likely because it has been assigned a custom sourcetype.

If Splunk knows about this sourcetype, how would I reference the proper configuration to get my line breaking to work properly for this source?

Splunk Employee
Love the idea! I am not seeing that Splunk has this. However, this is similar:

Also, as it relates to your question I would look at how this is done when using the Splunk Add-on for Tomcat (or maybe even use it):

Here are is another supporting link for installation / configuration should you go that route:

