If the sourcetype you want doesn't appear in the dropdown list, you can select "Manual" under "Set sourcetype", and then type in
answered 03 May '11, 09:03
the support solution go well
You should have a props.conf file in SPLUNK_HOME/etc/apps/legacy/default/
You should find a stanza that looks like this...
[windows_snare_syslog] pulldown_type = true
Make sure pulldown_type is set to true
answered 04 May '11, 01:34