問題文
A team receives web proxy logs from two different vendors through the same syslog collector. Both currently arrive with the same source type, and the field layout differs between them. What is the effect of leaving them under one source type, and what should the engineer do about it?
選択肢
- Splunk detects the layout of each individual event and applies the matching rules automatically, so a shared source type is harmless; the engineer only needs to confirm that both vendors are in the same index.
- Source types only affect how events are displayed in the search results list, so the layouts are parsed correctly either way; the engineer should leave the configuration alone and filter on the host field for each layout instead.
- The two layouts will be merged into a single normalized layout because they share a source type, so the engineer only has to add a search-time field alias that maps the merged layout onto the Common Information Model instead of separating the parsing rules at index time.
- One source type carries one set of parsing rules, so a single set of line-breaking, timestamp, and extraction rules is applied to both layouts; the engineer should split them into separate source types so each gets its own rules, which keeps each vendor's parsing settings independent.