For inputs.conf
, the more specific monitor path will override the general one, therefore your resque_events.log
will have the json_predefined_timestamp
sourcetype.
If you want to see how Splunk reads your inputs.conf
, then try the following command:
./splunk cmd btool inputs list --debug
http://docs.splunk.com/Documentation/Splunk/latest/admin/inputsconf