Customizing Source Types with Macros
When customizing security-content to fit your organization and Splunk deployment, one of the key things to change is what names your different source types have. A great example of this is sysmon data. If collected using the latest Splunk Add-On for Sysmon, it will automatically be source typed with sourcetype=XmlWinEventLog:Microsoft-Windows-Sysmon/Operational
This might not be the exact source type used in your organization and Splunk deployment. However, to set your own, simply modify the file: security-content/macros/sysmon.yml and change the value of definition. Other, great examples are okta, wmi, and streams http.