<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to edit props.conf in splunk cloud in Splunk Cloud Platform</title>
    <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-edit-props-conf-in-splunk-cloud/m-p/579197#M1237</link>
    <description>&lt;P&gt;Creating an app is pretty simple, at least once you have the hang of it.&lt;/P&gt;&lt;P&gt;Start with a Linux directory called 'myorg_httpevent_props'.&amp;nbsp; Replace "myorg" with an abbreviation of your company name.&amp;nbsp; There's nothing special about this name so you can use any name that doesn't conflict with another Splunk app (globally).&lt;/P&gt;&lt;P&gt;Create a subdirectory called "default" (it must be exactly that).&amp;nbsp; Within that directory, create three files: app.conf, props.conf, and transforms.conf.&amp;nbsp; The latter two will hold your configs from the OP.&amp;nbsp; The app. conf file tells Splunk about the app and will look something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[install]
state = enabled

[package]
check_for_updates = false
# The value below must match the directory name
id = myorg_httpevents_props

[ui]
is_visible = false

[launcher]
version = 1.0.0
author = &amp;lt;your name&amp;gt;
description = &amp;lt;some helpful text&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;chmod the flles with 644 and then put them into a compressed tarball.&amp;nbsp; Upload the tarball to your Splunk Cloud search head and wait for it to be vetted.&amp;nbsp; If vetting fails, read the report, make the necessary changes, and upload again.&amp;nbsp; (Delete the old upload before re-uploading.)&amp;nbsp; Once the app passes vetting you can install it.&lt;/P&gt;</description>
    <pubDate>Thu, 23 Dec 2021 17:49:41 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-12-23T17:49:41Z</dc:date>
    <item>
      <title>How to edit props.conf in splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-edit-props-conf-in-splunk-cloud/m-p/579191#M1234</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I need to filter data to reduce my ingestion volume and for that I need to change below two files. But I don't see these file in any option in splunk cloud platform. I am attaching the settings menu in splunk cloud. I have sc_admin privileges but still I don't see these files anywhere. Can you please let me know where to find these files and how to edit them in splunk clould ?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-12-23 at 8.55.53 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17337iE39A41446FAD305B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-12-23 at 8.55.53 PM.png" alt="Screenshot 2021-12-23 at 8.55.53 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;File props.conf&lt;/P&gt;&lt;P&gt;[httpevent]&lt;BR /&gt;TRANSFORMS-t1=eliminate-okhttp3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Below need to edit in&amp;nbsp;transforms.conf.&lt;/P&gt;&lt;P&gt;[eliminate-okhttp3]&lt;BR /&gt;REGEX = okhttp3&lt;BR /&gt;DEST_KEY = queue&lt;BR /&gt;FORMAT = nullQueue&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Dee&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 15:28:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-edit-props-conf-in-splunk-cloud/m-p/579191#M1234</guid>
      <dc:creator>splunk2xconnect</dc:creator>
      <dc:date>2021-12-23T15:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit props.conf in splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-edit-props-conf-in-splunk-cloud/m-p/579194#M1235</link>
      <description>&lt;P&gt;One cannot edit config files in Splunk Cloud.&lt;/P&gt;&lt;P&gt;The workaround is to create a custom app with your .conf settings and upload it to your cloud instance.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 16:18:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-edit-props-conf-in-splunk-cloud/m-p/579194#M1235</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-12-23T16:18:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit props.conf in splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-edit-props-conf-in-splunk-cloud/m-p/579195#M1236</link>
      <description>&lt;P&gt;Thanks for the quick response.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please elaborate on how to create custom apps ? Would we able able to move all our log sources (from which the logs are coming to Splunk) to this app ?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 17:04:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-edit-props-conf-in-splunk-cloud/m-p/579195#M1236</guid>
      <dc:creator>splunk2xconnect</dc:creator>
      <dc:date>2021-12-23T17:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit props.conf in splunk cloud</title>
      <link>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-edit-props-conf-in-splunk-cloud/m-p/579197#M1237</link>
      <description>&lt;P&gt;Creating an app is pretty simple, at least once you have the hang of it.&lt;/P&gt;&lt;P&gt;Start with a Linux directory called 'myorg_httpevent_props'.&amp;nbsp; Replace "myorg" with an abbreviation of your company name.&amp;nbsp; There's nothing special about this name so you can use any name that doesn't conflict with another Splunk app (globally).&lt;/P&gt;&lt;P&gt;Create a subdirectory called "default" (it must be exactly that).&amp;nbsp; Within that directory, create three files: app.conf, props.conf, and transforms.conf.&amp;nbsp; The latter two will hold your configs from the OP.&amp;nbsp; The app. conf file tells Splunk about the app and will look something like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[install]
state = enabled

[package]
check_for_updates = false
# The value below must match the directory name
id = myorg_httpevents_props

[ui]
is_visible = false

[launcher]
version = 1.0.0
author = &amp;lt;your name&amp;gt;
description = &amp;lt;some helpful text&amp;gt;&lt;/LI-CODE&gt;&lt;P&gt;chmod the flles with 644 and then put them into a compressed tarball.&amp;nbsp; Upload the tarball to your Splunk Cloud search head and wait for it to be vetted.&amp;nbsp; If vetting fails, read the report, make the necessary changes, and upload again.&amp;nbsp; (Delete the old upload before re-uploading.)&amp;nbsp; Once the app passes vetting you can install it.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Dec 2021 17:49:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Cloud-Platform/How-to-edit-props-conf-in-splunk-cloud/m-p/579197#M1237</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-12-23T17:49:41Z</dc:date>
    </item>
  </channel>
</rss>

