thanks Alemaruz, after changing the sourcetype, do i need to change anything in props.conf, transforms.conf, eventtype.conf and tags.conf.
In props.conf for the sourcetype=f5:big:syslog I could see below details and along with this stanza there are other stanza related to other sourcetypes. Should we need to remove them as i our case we have only one sourcetype is used to fetch the F5 LTM data into splunk.
Rename
General
[f5_bigip:syslog]
rename = f5:bigip:syslog
General
[f5:bigip:syslog]
SHOULD_LINEMERGE = false
LINE_BREAKER = ([\r\n]+)
TRANSFORMS-sourcetype=f5_bigip-irule-default, f5_bigip-irule-http, f5_bigip-irule-dns-request, f5_bigip-irule-dns-response, f5_bigip-irule-lb-failed, f5_bigip-syslog-asm, f5-bigip-apm-syslog, f5_bigip-irule-exclude-audit
Kindly guide me on this.
... View more