<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to edit the configuration files? in Installation</title>
    <link>https://community.splunk.com/t5/Installation/How-to-edit-the-configuration-files/m-p/80169#M9354</link>
    <description>&lt;P&gt;I have read this in a good many places that rather than playing with config files beforehand, it is always better to do it after providing the input and parsing , i.e. - dynamic searching. This may result in addition of fields when we use regex on the log event entries in the index obtained from Splunk.&lt;BR /&gt;
But making changes with regex for a particular field, then obtaining one of use and then saving it is also not an easy task, especially if you are not good at regex.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
    <pubDate>Thu, 21 Jun 2012 20:47:15 GMT</pubDate>
    <dc:creator>bhupinder_singh</dc:creator>
    <dc:date>2012-06-21T20:47:15Z</dc:date>
    <item>
      <title>How to edit the configuration files?</title>
      <link>https://community.splunk.com/t5/Installation/How-to-edit-the-configuration-files/m-p/80166#M9351</link>
      <description>&lt;P&gt;I am new to splunk. Could anyone please tell me how should I proceed in editing the .conf files in local directory? Are these changes critical to the parsing of the log files before they are indexed for search? I know that the inputs.conf and sourcetypes.conf has to be changed but I am not getting the required fields as per the log files, even if I do not make any changes at all.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2012 00:04:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-edit-the-configuration-files/m-p/80166#M9351</guid>
      <dc:creator>bhupinder_singh</dc:creator>
      <dc:date>2012-06-21T00:04:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit the configuration files?</title>
      <link>https://community.splunk.com/t5/Installation/How-to-edit-the-configuration-files/m-p/80167#M9352</link>
      <description>&lt;P&gt;The best place to start is here. &lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Tutorial/GetthesampledataintoSplunk"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Tutorial/GetthesampledataintoSplunk&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;For the basics of adding data to Splunk this will make changes to the config files for you.  For more advanced data there are examples and details in our online documentation as well.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2012 01:19:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-edit-the-configuration-files/m-p/80167#M9352</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-06-21T01:19:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit the configuration files?</title>
      <link>https://community.splunk.com/t5/Installation/How-to-edit-the-configuration-files/m-p/80168#M9353</link>
      <description>&lt;P&gt;Usually parsing rules and field extraction (index time and search-time) are in props.conf organized per sourcetype&lt;/P&gt;

&lt;P&gt;For index time, add it on the indexer, for search-time, on the search-head (if any).&lt;/P&gt;

&lt;P&gt;Remarks :&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;never edit the /default/ always create a new file in /local/ to contains your new settings and modifications.&lt;/LI&gt;
&lt;LI&gt;If you edit a config file, restart the splunk instance to apply.&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 21 Jun 2012 03:45:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-edit-the-configuration-files/m-p/80168#M9353</guid>
      <dc:creator>yannK</dc:creator>
      <dc:date>2012-06-21T03:45:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit the configuration files?</title>
      <link>https://community.splunk.com/t5/Installation/How-to-edit-the-configuration-files/m-p/80169#M9354</link>
      <description>&lt;P&gt;I have read this in a good many places that rather than playing with config files beforehand, it is always better to do it after providing the input and parsing , i.e. - dynamic searching. This may result in addition of fields when we use regex on the log event entries in the index obtained from Splunk.&lt;BR /&gt;
But making changes with regex for a particular field, then obtaining one of use and then saving it is also not an easy task, especially if you are not good at regex.&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2012 20:47:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-edit-the-configuration-files/m-p/80169#M9354</guid>
      <dc:creator>bhupinder_singh</dc:creator>
      <dc:date>2012-06-21T20:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: How to edit the configuration files?</title>
      <link>https://community.splunk.com/t5/Installation/How-to-edit-the-configuration-files/m-p/80170#M9355</link>
      <description>&lt;P&gt;I would recommend trying the field extractor.  That might help you get some of the extractions that aren't discovered automatically.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/5.0/Knowledge/ExtractfieldsinteractivelywithIFX"&gt;http://docs.splunk.com/Documentation/Splunk/5.0/Knowledge/ExtractfieldsinteractivelywithIFX&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2012 21:52:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Installation/How-to-edit-the-configuration-files/m-p/80170#M9355</guid>
      <dc:creator>sdaniels</dc:creator>
      <dc:date>2012-06-21T21:52:49Z</dc:date>
    </item>
  </channel>
</rss>

