can be:
1. , the source type of an event.
2. host:: , where is the host, or host-matching pattern, for an event.
3. source:: , where is the source, or source-matching pattern, for an event.
4. rule:: , where is a unique name of a source type classification rule.
5. delayedrule:: , where is a unique name of a delayed source type
classification rule.
These are only considered as a last resort before generating a new source type based on the
source seen.
... View more