I suggest you avoid doing this, but either:
[source::...]
What are you trying to do with a global transform that you can't do with a more specific source, sourcetype, or host pattern match?
To add to what gkanapathy said. I suggested against this. Especially the [source::...]
option. Because, if you add this stanza, then all other source-based props settings will no longer match. This is because this is because all first stanza to match so everything else will be ignore. See the docs: http://docs.splunk.com/Documentation/Splunk/5.0/admin/Propsconf
In other words, if you have a log file /var/log/httpd/error_log
, it will not be assigned the sourcetype of apache_error
, and WinEventLog
events will no longer be split apart properly, ...
Not that I've tried this to confirm the behavior, but it can't be good.
Just to note: Since 5.0 - you can now use the [default] stanza.
To add to what gkanapathy said. I suggested against this. Especially the [source::...]
option. Because, if you add this stanza, then all other source-based props settings will no longer match. This is because this is because all first stanza to match so everything else will be ignore. See the docs: http://docs.splunk.com/Documentation/Splunk/5.0/admin/Propsconf
In other words, if you have a log file /var/log/httpd/error_log
, it will not be assigned the sourcetype of apache_error
, and WinEventLog
events will no longer be split apart properly, ...
Not that I've tried this to confirm the behavior, but it can't be good.
I don't believe this is the case. All matching stanza rules in props.conf are applied to events.
I suggest you avoid doing this, but either:
[source::...]
What are you trying to do with a global transform that you can't do with a more specific source, sourcetype, or host pattern match?
A transform to pull information from a hostname and add fields accordingly (where the entire company conforms to a naming convention) would be useful for this as well, so it applies to all data.
I'm not sure what he is doing but I am trying to mask out credit card numbers no matter where they appear in any log.
Putting it at the top of the file works for me.