So as far as i can understand, you can define a common sourcename for several sourcetypes
I am using the webintelligence beta app, and this generates a sourcenames.csv file in /splunk/etc/apps/webintelligence/lookups
this looks like this:
But when i search for "sourcename" i does not find anything
What am i missing? i'm feeling ive read the manual on webintelligence and i cannot find any more info on this
asked 16 Apr '12, 11:59
If you want to search for a particular sourcename, use
Sourcename is not in the original event data so you must enrich the data through the lookup table.
Keep in mind you'll need to be within the web intelligence app as neither the lookup nor eventtype have global visibility.