I'm busting my head and I can't seem to get any where. I currently have all my F5 logs going into sourcetype f5:bigip:syslog and I would like to split the data into 2 and create 2 new sourcetypes, I'd like to do that based on the format of the data. Is there someone who can explain how to go about this? Basically I want to pull out the APM and http logs into the 2 new sourcetypes, that is what I want to achieve.
Logs are being sent in syslog via a UF so I know I need to do this on the Indexers. Will I have to create a custom app?