What's the best practice when adding event breakers to sources with different teams using the same source? E.g. suppose I have a splunk tcp input, and several teams are sending data to it. When I need non-default line breaking, I need to add them to the Event Breakers under Processing Settings. There, I can either add one rule set per team, and each rule set could have any number of rules (e.g. one for this sourcetype, another one for a second sourcetype). I could also add one rule set per sourcetype however. I feel like the Event Breaker rulesets exist to logically group the line breaking rules, e.g. by team - correct?
Question
Best practice when adding event breakers to sources with different teams using the same source?
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
