It looks like the four Data Inputs created by *NIX, including the Files and Directory Data Input for the /var/log directory, were disabled inside the Manager. So a quick click on 'enable' for each got me halfway there. I had a few custom logs sitting in the directory, so I modified the whitelist regex to include patterns for the names of the files, and now I'm all set!
... View more
Noah, you can ask another question with more specifics but what you want to do can be achieved using props/transforms.conf. Check the following: http://www.splunk.com/base/Documentation/4.1.4/Admin/Advancedsourcetypeoverrides
... View more