amiracle / homemonitor

Splunk app for home | monitor >
25 stars 5 forks source link

Change index & sourcetype #21

Open mamema opened 3 years ago

mamema commented 3 years ago

Hi,

i have homemonitor working with the provieded setup config. I have alsp the TA-pfsendse app running,because of other app and CIM requirement. Is it possible to change the index/sourcetype to the index/sourcetype of TA-pfsense, cause both apps ingest the same data and source. So my license usage is doubled and exceeds the daily limit. I've tried to change the index only, that breaks the app. So, can you help me to adapt the files please?

amiracle commented 3 years ago

My plan is to create a macro for the index and transition back to the main index to avoid any complications. For now, you can create a Splunk macro and call it home monitor then update the searches to include the macro for the index.