Hello,
I'm trying to parse three different log files with different regex.
I have three different sourcetypes for each, and I'm wondering how I can specify a different regex for each on props.conf.
Would it be as simple as
[sourcetype_one]
BREAK_ONLY_BEFORE= <regex>
[sourcetype_two]
...
Thank you, I would appreciate your ideas
Jack
Yes, it could be as simple as that. It's difficult to say for sure without seeing samples of your data.
The sourcetypes that you define in inputs.conf can be called out in stanzas in your props.conf, as you've mentioned above.
Correct, you make a stanza for each and in the stanza header you put one sourcetype, just like you showed in your question.