Hi!
I would like to get help if following configuration is possible or not.
I already have 1000 of events as sourcetype A in index A.
However , I want to use different stanza in props.conf for different purpose
perhaps as sourcetype B overriding sourcetype A.
Is such thing possible?
Any help is appreciated!
Thanks,
Yu
You can override the entire sourcetype or a subset of the events in the sourcetype. You can also rename the entire sourcetype or a subset of the events in the sourcetype. This is all well-documented:
http://docs.splunk.com/Documentation/Splunk/6.2.3/Data/Advancedsourcetypeoverrides