I have to index a log file in linux server in to one index but need to have two different sourcetype. Is it possible??
I tried but when compare
index = audit_idx sourcetype = linux_audit and index =audit_idx sourcetype = linux_audit_mll , results are not same there are few logs missing in each.
Want to know why its happening.
Thanks in advance..