I am trying to extract a field in Hunk, and I get the following error:
The events associated with this job have no sourcetype information
When I check one of the props.conf files, I see the source and sourcetype listed as such:
[source::/LogCentral/WindowsEvent/*/WindowsEventLogdata.*] sourcetype = windows_snare_syslog
However, running a search, the sourcetype field is not showing up.
Would appreciate any help...
Just a quick idea, your source path
/LogCentral/WindowsEvent//WindowsEventLogdata. looks pretty uncommon. Are you sure it isn't something like