Hi fellow Splunkers!
I'm curious to know what field extraction takes precedence if a field extraction is defined by the admin and shared with users and a user by himself created a second extraction slightly different in syntax for the same eventsource.
What extraction-definition takes precedence?
Thanks in advance!
Kind Regards,
pyro_wood
Hi Pyro!
In case you have a 'conflicting' extraction, admin will win. In the end it comes down to file precedence. There's a clear explanation of this in the manual, you can find it here:
http://docs.splunk.com/Documentation/Splunk/6.1/admin/Wheretofindtheconfigurationfiles
Specifically your user/admin battle is explained here:
http://dev.splunk.com/view/webframework-developapps/SP-CAAAE6T
However, try to avoid this if you can, because it is not always clear to the user what setting is applied. (could save you a lot of discussion 🙂
Cheers.
Hi Pyro!
In case you have a 'conflicting' extraction, admin will win. In the end it comes down to file precedence. There's a clear explanation of this in the manual, you can find it here:
http://docs.splunk.com/Documentation/Splunk/6.1/admin/Wheretofindtheconfigurationfiles
Specifically your user/admin battle is explained here:
http://dev.splunk.com/view/webframework-developapps/SP-CAAAE6T
However, try to avoid this if you can, because it is not always clear to the user what setting is applied. (could save you a lot of discussion 🙂
Cheers.
Thank you renems 🙂