<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What props.conf and transforms.conf settings I need to onboard my XML logs? and on which instances? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-props-conf-and-transforms-conf-settings-I-need-to-onboard/m-p/582549#M102626</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;First You should test this with sample data on your local dev instance. This is the easiest way to integrate data source to splunk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;On your local instance start with&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Settings -&amp;gt; Add Data -&amp;gt; Monitor/Upload&lt;/LI&gt;&lt;LI&gt;Select source file from your local disk&lt;/LI&gt;&lt;LI&gt;Configure the next parts&lt;OL&gt;&lt;LI&gt;Event Breaks (Regex&amp;nbsp;([\n\r]+)\s*&amp;lt;Interceptor&amp;gt;)&lt;/LI&gt;&lt;LI&gt;Timestamp: Advanced&lt;OL&gt;&lt;LI&gt;Format: %Y-%m-%d&amp;lt;/ActionDate&amp;gt;\n\s*&amp;lt;ActionTime&amp;gt;%H:%M%S (check with your actual data)&lt;/LI&gt;&lt;LI&gt;Prefix: &amp;lt;ActionDate&amp;gt;&lt;/LI&gt;&lt;LI&gt;Lookahead: enough long to match Format&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Advanced: If something is needed&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;When you are happy what you see on your preview, then "Save As" a new sourcetype. Also you can copy those with link "Copy to clipboard".&lt;/P&gt;&lt;P&gt;Then add that props.conf into the first full Splunk Enterprise instance on path from your source system to indexers. And remember restart that instance.&lt;/P&gt;&lt;P&gt;I prefer to create own TA for those config and then distribute that TA where it is needed.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Wed, 26 Jan 2022 14:55:50 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2022-01-26T14:55:50Z</dc:date>
    <item>
      <title>What props.conf and transforms.conf settings I need to onboard my XML logs? and on which instances?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-props-conf-and-transforms-conf-settings-I-need-to-onboard/m-p/582523#M102624</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="trabz777_0-1643197346946.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/17678iD21BAF0D9141329E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="trabz777_0-1643197346946.png" alt="trabz777_0-1643197346946.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;This ^ is sample xml log file that I want to onboard. Please guide me about the settings which I should set in order to properly input this data. Also tell me on which instances the settings (props.conf and transforms.conf) are required. I am running a Distributed system with indexer clustering.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 11:45:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-props-conf-and-transforms-conf-settings-I-need-to-onboard/m-p/582523#M102624</guid>
      <dc:creator>trabz777</dc:creator>
      <dc:date>2022-01-26T11:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: What props.conf and transforms.conf settings I need to onboard my XML logs? and on which instances?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-props-conf-and-transforms-conf-settings-I-need-to-onboard/m-p/582549#M102626</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;First You should test this with sample data on your local dev instance. This is the easiest way to integrate data source to splunk.&amp;nbsp;&lt;/P&gt;&lt;P&gt;On your local instance start with&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;Settings -&amp;gt; Add Data -&amp;gt; Monitor/Upload&lt;/LI&gt;&lt;LI&gt;Select source file from your local disk&lt;/LI&gt;&lt;LI&gt;Configure the next parts&lt;OL&gt;&lt;LI&gt;Event Breaks (Regex&amp;nbsp;([\n\r]+)\s*&amp;lt;Interceptor&amp;gt;)&lt;/LI&gt;&lt;LI&gt;Timestamp: Advanced&lt;OL&gt;&lt;LI&gt;Format: %Y-%m-%d&amp;lt;/ActionDate&amp;gt;\n\s*&amp;lt;ActionTime&amp;gt;%H:%M%S (check with your actual data)&lt;/LI&gt;&lt;LI&gt;Prefix: &amp;lt;ActionDate&amp;gt;&lt;/LI&gt;&lt;LI&gt;Lookahead: enough long to match Format&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;LI&gt;Advanced: If something is needed&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;When you are happy what you see on your preview, then "Save As" a new sourcetype. Also you can copy those with link "Copy to clipboard".&lt;/P&gt;&lt;P&gt;Then add that props.conf into the first full Splunk Enterprise instance on path from your source system to indexers. And remember restart that instance.&lt;/P&gt;&lt;P&gt;I prefer to create own TA for those config and then distribute that TA where it is needed.&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Wed, 26 Jan 2022 14:55:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-props-conf-and-transforms-conf-settings-I-need-to-onboard/m-p/582549#M102626</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2022-01-26T14:55:50Z</dc:date>
    </item>
  </channel>
</rss>

