We have the need to set a high level sourcetype in the inputs.conf to one sourcetype and override some of those sources using the prop.conf and provide a more meaningful sourcetype. This didn't work however, when I removed the sourcetype from the inputs.conf the props.conf went ahead and overrode the the automatic designation splunk assigned as expected.
The goal is to set all data to one sourcetype with inputs.conf and override sourcetypes for selected files with a specific info in the props.conf.
Note that we are indexing archive files directly that have several levels.
Should this be possible?
Splunk 5.0.4 build 172409.
... View more