Hi,
What is the best practice when looking at syslogs:
Split the syslog into multiple files, one for each source type (e.g. mail, syslog, apache, etc.) and then apply one source type to each file.
Read in the syslog and then have the indexer apply the source type based upon entries in the transforms and props files.
What are the pluses and minutes of each option.
cheers,
ski
... View more