|
I have a single source and my main config is based on overided sourcetypes. So is it save to build all configs (FIELDALIAS, LOOKUP, REPORTS) under this overrided sourcetypes? |
|
FIELDALIAS, LOOKUP, and REPORT are all search time configurations which are perfectly acceptable to run on a sourcetype which is set via TRANSFORMS or sourcetype= property on a particular source. But note that of course non-search-time configs (TRANSFORM, TZ, etc, see http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F for a non-exhaustive list) won't work with those, and note that if you use the "rename" directive to override a sourcetype, no settings (including search search-time) can be applied.
(18 Apr '11, 10:31)
gkanapathy ♦
|