Hi fellow Splunkers!
I'm curious to know what field extraction takes precedence if a field extraction is defined by the admin and shared with users and a user by himself created a second extraction slightly different in syntax for the same eventsource.
What extraction-definition takes precedence?
Thanks in advance!
In case you have a 'conflicting' extraction, admin will win. In the end it comes down to file precedence. There's a clear explanation of this in the manual, you can find it here:
Specifically your user/admin battle is explained here:
However, try to avoid this if you can, because it is not always clear to the user what setting is applied. (could save you a lot of discussion 🙂
View solution in original post
Thank you renems 🙂