What's the best practice when adding event breakers to sources with different teams using the same source? E.g. suppose I have a splunk tcp input, and several teams are sending data to it. When I need non-default line breaking, I need to add them to the Event Breakers under Processing Settings. There, I can either add one rule set per team, and each rule set could have any number of rules (e.g. one for this sourcetype, another one for a second sourcetype). I could also add one rule set per sourcetype however. I feel like the Event Breaker rulesets exist to logically group the line breaking rules, e.g. by team - correct?
Question
Best practice when adding event breakers to sources with different teams using the same source?
Sign up
Already have an account? Login
Login to the community
No account yet? Create an account
Using your Cribl Curious or University Account
User Login Employee loginEnter your E-mail address. We'll send you an e-mail with instructions to reset your password.
