Hello
I'm new to Splunk and one of my first testings was to create a sourcetype reexp to filter special data. Now in the next step, I try to move this sourcetypes to a special index.
My question now is, is this possible that splunk recognize that this data is in that format and write it to the special index. Or is it not possible because at the recognize process, the data have been written to the default index ?
Thanks
R