Getting Data In

Why is Splunk ignoring my [<sourcetype>] in props.conf?

Grady
Engager

I've been fighting with what seems to be a simple configuration to input a nonstandard text format for 2 days now. The only configuration that I believe I need in the sourcetype stanza in props is a BREAK_ONLY_BEFORE. The configuration makes perfect sense but it simply isn't working. In fact, when I manually set the sourcetype the indexer finds no events at all. When left on automatic it finds events but they're not valid or malformed.

Tags (1)
0 Karma
1 Solution

Grady
Engager

After a full day of poring over the answers here, I find this buried away where it took forever to find:

http://answers.splunk.com/questions/7191/log-file-not-breaking-correctly/7211#7211

And what do you know. There were a number of incorrect assumptions tucked away in the learned app files, including some entries in files other than props. Cleaning those out made everything work like the magic I was expecting.

Thanks meno!

View solution in original post

Grady
Engager

After a full day of poring over the answers here, I find this buried away where it took forever to find:

http://answers.splunk.com/questions/7191/log-file-not-breaking-correctly/7211#7211

And what do you know. There were a number of incorrect assumptions tucked away in the learned app files, including some entries in files other than props. Cleaning those out made everything work like the magic I was expecting.

Thanks meno!

Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer at Splunk .conf24 ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...