feb 01 10:24:12 myhostname 2025-02-01 10:24:12,999, myhostname, audit.admin.com.cd.etc info  feb 01 10:24:12 myhostname 2025-02-01 10:24:12,999, myhostname, audit.system.com.cd.etc info  inputs.conf   sourcetype = rsa:syslog  my props.conf     I would like to change sourcetype base "admin", OR "system" depend on raw events.  [rsa:syslog]  TRANSFORMS-change_sourcetype = change_admin_sourcetype, change_system_sourcetype  my transforms.conf  [change_admin_sourcetype]  DESK_KEY = MetaData:Sourcetype  REGEX = \,\s+adudit\.admin  FORMAT = sourcetype::rsa:admin  [change_system_sourcetype]  DESK_KEY = MetaData:Sourcetype  REGEX = \,\s+adudit\.system  FORMAT = sourcetype::rsa:system     but it doesnt' work.  thank you for your help. 
						
					
					... View more