Hi guys, I have several topics on the table. 1) I would like to know if you would have any advice, process or even document defining the principles of creating a naming convention when it comes to sourcetypes. We have faced the classic issue where some of our sourcetypes had the same name and we would like to find ways to avoid that from now on. 2) Is it pertinent to add predefined / learned sourcetypes with a naming convention based on the format.? (then we could solve the point 1 with a naming convention like app_format for example). How do you technically add new predefined sourcetypes and how do you solve both the management of sourcetypes (point 1) and the management of predefined sourcetypes ? 3) How do you share Knowledge Objects, props and transforms between 2 Search Head clusters, how do you implement a continuously synced mechanism that would keep these objects synced between both clusters ? Do we have to use Ansible deployments to perform the changes on both clusters or is there any Splunk way to achieve this synchronization in an easier way inside Splunk (via a script using REST API, command line, configuration etc) ?
... View more