March 2018
Beginner to intermediate
576 pages
13h 29m
English
As you dig into configurations, you will see attribute names of the FOO-bar form.
The word after the dash is generally referred to as the class. These attributes are special in a few ways:
sourcetype=foo_type source=/logs/abc/def/gh.log host=dns4.nyc.mycompany.com
And, say this is the configuration snippet:
[foo_type] TRANSFORMS-a = from_sourcetype1, from_sourcetype2 [source::/logs/.../*.log] TRANSFORMS-c = from_source_b ...
Read now
Unlock full access