<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: KV_MODE=json in Other Admin</title>
    <link>https://community.splunk.com/t5/Other-Admin/KV-MODE-json/m-p/709053#M80</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264857"&gt;@kiran_panchavat&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;We already have props.conf for same sourcetype in a app in DS which we push to manager node and manager will distribute to indexers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now my question is can I include my kv_mode in same props.conf and push it to deployer (so that it will push to SHs) but it has line breaker bla bla in it.&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;should I create new app in deployer and then in local new props.conf and push it to SHs?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;And we need all data (all sourcetypes) to follow this KV_MODE=json... Is there any way I can give by default rather than specifying each sourcetype seperately?&lt;/P&gt;</description>
    <pubDate>Fri, 17 Jan 2025 06:32:26 GMT</pubDate>
    <dc:creator>splunklearner</dc:creator>
    <dc:date>2025-01-17T06:32:26Z</dc:date>
    <item>
      <title>KV_MODE=json</title>
      <link>https://community.splunk.com/t5/Other-Admin/KV-MODE-json/m-p/709011#M76</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I wanted to know where I should keep this attribute&amp;nbsp;KV_MODE=json to extract the json fields automatically? In Deployment server or manager node or deployer?&lt;/P&gt;&lt;P&gt;We have props.conf in a app in DS. DS push that app to manager node. And manager will distribute that app to peer nodes. Can I add this in that props.conf?&lt;/P&gt;&lt;P&gt;Or any alternative please suggest.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2025 17:21:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Admin/KV-MODE-json/m-p/709011#M76</guid>
      <dc:creator>splunklearner</dc:creator>
      <dc:date>2025-01-16T17:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: KV_MODE=json</title>
      <link>https://community.splunk.com/t5/Other-Admin/KV-MODE-json/m-p/709012#M77</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273723"&gt;@splunklearner&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;the props.conf must be deployed to the Search Heads (using the SHC-Deployer if you have a cluster).&lt;/P&gt;&lt;P&gt;and to the Forwarder that ingest logs, using the DS.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 07:19:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Admin/KV-MODE-json/m-p/709012#M77</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2025-01-17T07:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: KV_MODE=json</title>
      <link>https://community.splunk.com/t5/Other-Admin/KV-MODE-json/m-p/709014#M78</link>
      <description>&lt;P&gt;Second point I didn't get you. We have a seperate syslog server where UF is installed and from there logs will be forwarded to our DS. what can I do now?&lt;/P&gt;&lt;P&gt;Do I need to give props.conf on both deployer and forwarder?&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jan 2025 17:53:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Admin/KV-MODE-json/m-p/709014#M78</guid>
      <dc:creator>splunklearner</dc:creator>
      <dc:date>2025-01-16T17:53:34Z</dc:date>
    </item>
    <item>
      <title>Re: KV_MODE=json</title>
      <link>https://community.splunk.com/t5/Other-Admin/KV-MODE-json/m-p/709051#M79</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273723"&gt;@splunklearner&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;To extract key-value pairs from JSON data during searches, configure props.conf with KV_MODE=JSON. If you have a Splunk deployment with a Search Head Cluster (SHC), use the deployer to push this configuration to all search heads. Keep in mind that props.conf on Universal Forwarders has limited functionality.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;refer this&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.aplura.com/assets/pdf/where_to_put_props.pdf" target="_blank"&gt;https://www.aplura.com/assets/pdf/where_to_put_props.pdf&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 05:21:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Admin/KV-MODE-json/m-p/709051#M79</guid>
      <dc:creator>kiran_panchavat</dc:creator>
      <dc:date>2025-01-17T05:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: KV_MODE=json</title>
      <link>https://community.splunk.com/t5/Other-Admin/KV-MODE-json/m-p/709053#M80</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/264857"&gt;@kiran_panchavat&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;We already have props.conf for same sourcetype in a app in DS which we push to manager node and manager will distribute to indexers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now my question is can I include my kv_mode in same props.conf and push it to deployer (so that it will push to SHs) but it has line breaker bla bla in it.&lt;/P&gt;&lt;P&gt;or&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;should I create new app in deployer and then in local new props.conf and push it to SHs?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;And we need all data (all sourcetypes) to follow this KV_MODE=json... Is there any way I can give by default rather than specifying each sourcetype seperately?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 06:32:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Admin/KV-MODE-json/m-p/709053#M80</guid>
      <dc:creator>splunklearner</dc:creator>
      <dc:date>2025-01-17T06:32:26Z</dc:date>
    </item>
    <item>
      <title>Re: KV_MODE=json</title>
      <link>https://community.splunk.com/t5/Other-Admin/KV-MODE-json/m-p/709057#M81</link>
      <description>You can deploy the same props.conf to all nodes if you want. Each node use that part of it which have configuration which affects its behavior. Of course you must ensure that you don’t set twice e.g json handling with different way one for indexing and another for search. This leads you to see duplicate events.</description>
      <pubDate>Fri, 17 Jan 2025 07:14:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Admin/KV-MODE-json/m-p/709057#M81</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2025-01-17T07:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: KV_MODE=json</title>
      <link>https://community.splunk.com/t5/Other-Admin/KV-MODE-json/m-p/709114#M82</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp;but if give same props.conf with KV_MODE=json and distribute it to both indexers and search heads, will it lead to duplication of events or is it fine?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jan 2025 18:44:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Other-Admin/KV-MODE-json/m-p/709114#M82</guid>
      <dc:creator>splunklearner</dc:creator>
      <dc:date>2025-01-17T18:44:38Z</dc:date>
    </item>
  </channel>
</rss>

