Getting Data In
Highlighted

Can you treat overrided sourcetypes savely as normal sourcetypes?

Contributor

I have a single source and my main config is based on overided sourcetypes.
So is it save to build all configs (FIELDALIAS, LOOKUP, REPORTS) under this overrided sourcetypes?

Tags (1)
0 Karma
Highlighted

Re: Can you treat overrided sourcetypes savely as normal sourcetypes?

Builder

FIELDALIAS, LOOKUP, and REPORT are all search time configurations which are perfectly acceptable to run on a sourcetype which is set via TRANSFORMS or sourcetype= property on a particular source.

Highlighted

Re: Can you treat overrided sourcetypes savely as normal sourcetypes?

Legend

But note that of course non-search-time configs (TRANSFORM, TZ, etc, see http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F for a non-exhaustive list) won't work with those, and note that if you use the "rename" directive to override a sourcetype, no settings (including search search-time) can be applied.

0 Karma