When using a directory monitor input, specific source type can be selectively overridden using which configuration file?
When using a directory monitor input, specific source type can be selectively overridden using which configuration file?
To selectively override the source type when using a directory monitor input, you should use the props.conf configuration file. This file allows the specification of various data processing properties, including overriding source types for different input data.
see Splunk Enterprise 9.0 Data Administration, page 255
Why not A and D
outputs.conf only has configurations regarding the server that will receive the data, being a Heavy Forwarder or an Indexer and how.