I have different types of log coming into splunk via mod input and the logs are being ingested into Kafka topic event.
I need to override the logs based on some field or some way to multiple sourcetype