Hi,
I have a novice question, but is it possible to have more than one sourcetype for a given source?
Sure.
In props.conf
[source::<your source name>]
TRANSFORMS-XXX = AAA
TRANSFORMS-YYY = BBB
...
In transforms.conf
[AAA]
REGEX = <Extract a trait in your log like host IP or something else>
DEST_KEY = MetaData:Sourcetype
FORMAT = sourcetype::<your sourcetype name>
[BBB]
...