Hi, I'm new to Splunk here... I have a local instance of Splunk Enterprise on my local machine where I've created a data input via Data Input > Files & Directories, and then created an Index which I then map the data input to. Within this folder, I've dumped various types of log files from different formats / types of web servers e.g. Apache webserver and IIS , even JSON-formatted log files for analysis. When I do search for a field name that exists in log files from different formats, does the search results come out for both? Is there any link/doc that explains the best practices or how Splunk behaves with regards to how data is indexed in this circumstance? Thanks in advance.
... View more