Getting Data In
Highlighted

Can you treat overrided sourcetypes savely as normal sourcetypes?

Contributor

I have a single source and my main config is based on overided sourcetypes.
So is it save to build all configs (FIELDALIAS, LOOKUP, REPORTS) under this overrided sourcetypes?

Tags (1)
0 Karma
Highlighted

Re: Can you treat overrided sourcetypes savely as normal sourcetypes?

Builder

FIELDALIAS, LOOKUP, and REPORT are all search time configurations which are perfectly acceptable to run on a sourcetype which is set via TRANSFORMS or sourcetype= property on a particular source.

Highlighted

Re: Can you treat overrided sourcetypes savely as normal sourcetypes?

Legend

But note that of course non-search-time configs (TRANSFORM, TZ, etc, see http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F for a non-exhaustive list) won't work with those, and note that if you use the "rename" directive to override a sourcetype, no settings (including search search-time) can be applied.

0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.