<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Use of wildcard in props.conf in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-put-that-source-in-props-conf-without-listing-each-one/m-p/604997#M105188</link>
    <description>&lt;P&gt;Yes, you can use the sourcetype on the props.conf instead of the sources.&amp;nbsp;&lt;BR /&gt;You can check it on the docs:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.0/Admin/Propsconf#GLOBAL_SETTINGS" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.0/Admin/Propsconf#GLOBAL_SETTINGS&lt;/A&gt;&lt;/P&gt;&lt;PRE&gt;[&amp;lt;spec&amp;gt;]
* This stanza enables properties for a given &amp;lt;spec&amp;gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;PRE&gt;&amp;lt;spec&amp;gt; can be:
1. &amp;lt;sourcetype&amp;gt;, the source type of an event.&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 08 Jul 2022 18:55:27 GMT</pubDate>
    <dc:creator>danielcj</dc:creator>
    <dc:date>2022-07-08T18:55:27Z</dc:date>
    <item>
      <title>How can I put that source in props.conf without listing each one separately?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-put-that-source-in-props-conf-without-listing-each-one/m-p/604990#M105185</link>
      <description>&lt;P&gt;We are trying to filter out events from a Syslog server that is ingesting data for a number of sources but the one we are trying to filter is from our Meraki devices.&amp;nbsp; Each Meraki is considered a source and the sourcetype is meraki.&amp;nbsp; This is a sample of the events coming into Splunk:&lt;/P&gt;
&lt;P&gt;2022-07-08 07:14:51.427 xxx.xxx.xxx.xxx 1 Location_XXX flows src=xxx.xxx.0.1 dst=8.8.8.8 mac=70:D3:79:XX:XX:XX protocol=icmp type=8 pattern: allow icmp&lt;BR /&gt;host = xxx.xx.0.2source = /syslog0/syslog/meraki/xxx.xx.0.2/messages.log sourcetype = meraki&lt;/P&gt;
&lt;P&gt;There are more than 100 sources all using the format:&amp;nbsp; /syslog0/syslog/meraki/&amp;lt;IP Address&amp;gt;/messages.log&lt;/P&gt;
&lt;P&gt;How can I put that source in props.conf without listing each one separately?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 20:34:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-put-that-source-in-props-conf-without-listing-each-one/m-p/604990#M105185</guid>
      <dc:creator>leejones4</dc:creator>
      <dc:date>2022-07-08T20:34:50Z</dc:date>
    </item>
    <item>
      <title>Re: Use of wildcard in props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-put-that-source-in-props-conf-without-listing-each-one/m-p/604993#M105186</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224844"&gt;@leejones4&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;You could use the sourcetype definition instead of the sources on the props.conf file&lt;/P&gt;&lt;P&gt;For example:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;props.conf file

[meraki]
&amp;lt;YOUR_DEFINITIONS_HERE&amp;gt;
&lt;/LI-CODE&gt;</description>
      <pubDate>Fri, 08 Jul 2022 18:41:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-put-that-source-in-props-conf-without-listing-each-one/m-p/604993#M105186</guid>
      <dc:creator>danielcj</dc:creator>
      <dc:date>2022-07-08T18:41:59Z</dc:date>
    </item>
    <item>
      <title>Re: Use of wildcard in props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-put-that-source-in-props-conf-without-listing-each-one/m-p/604996#M105187</link>
      <description>&lt;P&gt;That's awesome.&amp;nbsp; So I don't need to put the source but can use the sourcetype instead?&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 18:53:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-put-that-source-in-props-conf-without-listing-each-one/m-p/604996#M105187</guid>
      <dc:creator>leejones4</dc:creator>
      <dc:date>2022-07-08T18:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: Use of wildcard in props.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-put-that-source-in-props-conf-without-listing-each-one/m-p/604997#M105188</link>
      <description>&lt;P&gt;Yes, you can use the sourcetype on the props.conf instead of the sources.&amp;nbsp;&lt;BR /&gt;You can check it on the docs:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.0/Admin/Propsconf#GLOBAL_SETTINGS" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.0.0/Admin/Propsconf#GLOBAL_SETTINGS&lt;/A&gt;&lt;/P&gt;&lt;PRE&gt;[&amp;lt;spec&amp;gt;]
* This stanza enables properties for a given &amp;lt;spec&amp;gt;.&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;PRE&gt;&amp;lt;spec&amp;gt; can be:
1. &amp;lt;sourcetype&amp;gt;, the source type of an event.&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 18:55:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-put-that-source-in-props-conf-without-listing-each-one/m-p/604997#M105188</guid>
      <dc:creator>danielcj</dc:creator>
      <dc:date>2022-07-08T18:55:27Z</dc:date>
    </item>
  </channel>
</rss>

