Hello,
I have to index a log file in linux server in to one index but need to have two different sourcetype. Is it possible??
I tried but when compare
index = audit_idx sourcetype = linux_audit and index =audit_idx sourcetype = linux_audit_mll , results are not same there are few logs missing in each.
Want to know why its happening.
Thanks in advance..
Hi
you can use CLONE_SOURCETYPE to clone same event to the different sourcetype. You should remember that it duplicates your license usage!
https://docs.splunk.com/Documentation/Splunk/latest/Admin/Transformsconf
r. Ismo