feb 01 10:24:12 myhostname 2025-02-01 10:24:12,999, myhostname, audit.admin.com.cd.etc info feb 01 10:24:12 myhostname 2025-02-01 10:24:12,999, myhostname, audit.system.com.cd.etc info inputs.conf sourcetype = rsa:syslog my props.conf I would like to change sourcetype base "admin", OR "system" depend on raw events. [rsa:syslog] TRANSFORMS-change_sourcetype = change_admin_sourcetype, change_system_sourcetype my transforms.conf [change_admin_sourcetype] DESK_KEY = MetaData:Sourcetype REGEX = \,\s+adudit\.admin FORMAT = sourcetype::rsa:admin [change_system_sourcetype] DESK_KEY = MetaData:Sourcetype REGEX = \,\s+adudit\.system FORMAT = sourcetype::rsa:system but it doesnt' work. thank you for your help.
... View more