<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: One Search Head ignores props.conf One Does Not in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/562634#M100265</link>
    <description>&lt;P&gt;Remember that btool shows the current configs *on disk* rather than those currently in use.&amp;nbsp; IOW, btool shows what Splunk will load the next time it restarts.&amp;nbsp; Have you tried restarting the old SH?&lt;/P&gt;</description>
    <pubDate>Mon, 09 Aug 2021 16:50:16 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-08-09T16:50:16Z</dc:date>
    <item>
      <title>One Search Head ignores props.conf One Does Not</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/562581#M100260</link>
      <description>&lt;P&gt;We have 3 clustered indexers and an original Search Head. Installed an app that has a custom props.conf on the Search Head, and it is NOT showing the extracted proper fields when performing searches.&lt;/P&gt;&lt;P&gt;Deployed a new Search Head and installed the same exact app. The new Search Head shows the proper fields. The two servers appear to be identical, and running:&lt;/P&gt;&lt;P&gt;splunk cmd btool props list --debug&lt;/P&gt;&lt;P&gt;...shows the same exact results, line by line, for the app. The original server does have some extra apps, but with the results of the btool above, it would not appear there are any conflicts with other apps.&lt;/P&gt;&lt;P&gt;What would be the next steps in troubleshooting the original Search Head, and why it does not show the proper fields?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 12:49:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/562581#M100260</guid>
      <dc:creator>dbray_sd</dc:creator>
      <dc:date>2021-08-09T12:49:29Z</dc:date>
    </item>
    <item>
      <title>Re: One Search Head ignores props.conf One Does Not</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/562634#M100265</link>
      <description>&lt;P&gt;Remember that btool shows the current configs *on disk* rather than those currently in use.&amp;nbsp; IOW, btool shows what Splunk will load the next time it restarts.&amp;nbsp; Have you tried restarting the old SH?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 16:50:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/562634#M100265</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-08-09T16:50:16Z</dc:date>
    </item>
    <item>
      <title>Re: One Search Head ignores props.conf One Does Not</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/562635#M100266</link>
      <description>&lt;P&gt;Sorry, yes of course. I've even gone as far as updating the entire environment to the latest Splunk version, to make sure it was not some older bug. So now, everything is upgraded to the latest released version, and restarted.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 17:00:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/562635#M100266</guid>
      <dc:creator>dbray_sd</dc:creator>
      <dc:date>2021-08-09T17:00:21Z</dc:date>
    </item>
    <item>
      <title>Re: One Search Head ignores props.conf One Does Not</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/562636#M100267</link>
      <description>&lt;P&gt;Did it behave same way independent which user is running your query? It could be that in old sh there is private props definition which is not present in new sh.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 16:53:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/562636#M100267</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-08-09T16:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: One Search Head ignores props.conf One Does Not</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/562637#M100268</link>
      <description>&lt;P&gt;Good theory, but no, that's not it. All users are having the issue on the old server, but not the new.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 16:56:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/562637#M100268</guid>
      <dc:creator>dbray_sd</dc:creator>
      <dc:date>2021-08-09T16:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: One Search Head ignores props.conf One Does Not</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/562638#M100269</link>
      <description>&lt;P&gt;You have same roles on both SHs without any search filters defined? So search logs are identical?&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 17:01:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/562638#M100269</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-08-09T17:01:08Z</dc:date>
    </item>
    <item>
      <title>Re: One Search Head ignores props.conf One Does Not</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/562640#M100270</link>
      <description>&lt;P&gt;Yes, same roles same, LDAP settings, same everything (as far as I can tell). No search filters defined.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 17:01:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/562640#M100270</guid>
      <dc:creator>dbray_sd</dc:creator>
      <dc:date>2021-08-09T17:01:54Z</dc:date>
    </item>
    <item>
      <title>Re: One Search Head ignores props.conf One Does Not</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/562701#M100274</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/146904"&gt;@dbray_sd&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;Check in which app context you are running the searches. In the app-user context, configurations in the&amp;nbsp;&lt;SPAN&gt;currently running app take precedence over&amp;nbsp;all other apps configurations even though btool lists those.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;From the Splunk documentation:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Precedence within the app or user context:&lt;/STRONG&gt;&lt;BR /&gt;For files with an app/user context, directory priority descends from user to app to the system:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;1. User directories for &lt;STRONG&gt;current user&lt;/STRONG&gt; -- highest priority&lt;BR /&gt;2. App directories for &lt;STRONG&gt;currently running app&lt;/STRONG&gt; (local, followed by default)&lt;BR /&gt;3. App directories for all other apps (local, followed by default) -- for exported settings only&lt;BR /&gt;4. System directories (local, followed by default) -- lowest priority&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 02:38:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/562701#M100274</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2021-08-10T02:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: One Search Head ignores props.conf One Does Not</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/562729#M100277</link>
      <description>&lt;P&gt;Not really sure I understand exactly what you are asking to confirm. The app doesn't matter. I can duplicate this issue in our customized app, in the Search &amp;amp; reporting app, or any other place. The particular app that contains the specific props.conf file is set with Global permissions.&lt;/P&gt;&lt;P&gt;In the new working SH, it also doesn't matter where or how I perform the searches. It always uses the Global permissions on the props.conf file, and always works.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 11:55:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/562729#M100277</guid>
      <dc:creator>dbray_sd</dc:creator>
      <dc:date>2021-08-11T11:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: One Search Head ignores props.conf One Does Not</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/563623#M100402</link>
      <description>&lt;P&gt;Unfortunately, I had to give up on my investigation, and ended up re-installing the broke SH.&lt;/P&gt;&lt;P&gt;I removed Splunk, reinstalled the same rpm, reinstalled the same troublesome app, and everything worked (as expected). Then, I moved one app back in at a time, each time checking the original broke props.conf/app and each time everything continued to work. So, no real good idea what was causing the issue, but everything is working now.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Aug 2021 11:18:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/One-Search-Head-ignores-props-conf-One-Does-Not/m-p/563623#M100402</guid>
      <dc:creator>dbray_sd</dc:creator>
      <dc:date>2021-08-17T11:18:54Z</dc:date>
    </item>
  </channel>
</rss>

