Log Source Types are used to classify logs that come from common hardware or have the same data format and operate under the same processing rules. Using a Log Source Type improves processing performance because logs are only processed against rules for that type. Rules for other Log Sources Types are automatically skipped.
Examples of a Log Source Type:
- An in-house software application
- The Windows Application Event Log
One Log Source Type is assigned to each Log Message Source and to collections of rules defined in Log Processing Policies. That way, LogRhythm knows which rules can be assigned to which Log Message Sources.