When adding a directory monitor and specifying a sourcetype explicitly, it applies to all files in the directory and subdirectories. If automatic sourcetyping is used, a user can selectively override it in which file on the forwarder?
When a directory monitor is set up with automatic sourcetyping, a user can selectively override the sourcetype assignment by configuring the props.conf file on the forwarder. The props.conf file allows you to define how data should be parsed and processed, including assigning or overriding sourcetypes for specific data inputs.
Splunk Documentation Reference: props.conf configuration
Lashaunda
2 days agoDelmy
14 days agoJohnetta
15 days agoAlexia
18 days agoEthan
18 days agoWillodean
4 days agoEric
20 days agoYuki
2 days agoOlga
10 days ago