- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
imrago
Contributor
08-10-2010
01:22 AM
On splunkA I am monitoring an xml log file. It is forwarded to SplunkB in a separate index. Where should I define the multiline event breaking and the field extraction? On sender(splunkA) or receiver(splunkB)?
1 Solution
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
gkanapathy

Splunk Employee
08-10-2010
06:52 AM
Please see: http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F to learn how to determine where a configuration needs to reside.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
gkanapathy

Splunk Employee
08-10-2010
06:52 AM
Please see: http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F to learn how to determine where a configuration needs to reside.
