Hi All,
We are in the process of onboarding logs from a centralized log server, where all endpoints forward their logs. We have installed a Splunk Heavy Forwarder on the server to monitor and forward these logs to the Indexers.
I would like to know if there are any default sourcetypes available for data sources such as systemd.log and sudo.log
Hi @kumva01 As you tagged Splunk Addon for Unix and Linux, i assume you are using this addon.
if yes, then the addon will take care of the sourcetype automatically.
here is the list of sourcetypes of the unix/linux addon:
https://docs.splunk.com/Documentation/AddOns/released/UnixLinux/Sourcetypes
and here is the list of pretrained sourcetypes:
https://docs.splunk.com/Documentation/Splunk/9.3.1/Data/Listofpretrainedsourcetypes
Pls suggest more details about your question, thanks.