<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Props Conf File in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562324#M195569</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;can you describe what you want to get by props (e.g. some fields defined or drop events or ....)?&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
    <pubDate>Thu, 05 Aug 2021 22:05:08 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2021-08-05T22:05:08Z</dc:date>
    <item>
      <title>Props Conf File</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562319#M195565</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How would I write the props config file for following events, any help will be highly appreciated, thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;Thu, 01 Jul 2021 00:20:04 -0400|system|flush_vulns|INFO|-1|Removing old data in Repository&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;Thu, 01 Jul 2021 00:20:04 -0400|system|flush_vulns|INFO|-1|Successful removal of old &amp;nbsp;data in Repository&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;Thu, 01 Jul 2021 00:20:05 -0400|system|flush_vulns|INFO|-1|Removing old data in Repository&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;Thu, 01 Jul 2021 00:20:05 -0400|system|flush_vulns|INFO|-1|Successful removal of old data in Repository&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 21:31:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562319#M195565</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-05T21:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: Props Conf File</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562324#M195569</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;can you describe what you want to get by props (e.g. some fields defined or drop events or ....)?&lt;/P&gt;&lt;P&gt;r. Ismo&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 22:05:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562324#M195569</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-08-05T22:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: Props Conf File</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562326#M195571</link>
      <description>&lt;P&gt;Thank you so much. I stuck writing my TIME_PREFIX and TIME_FORMAT in Props Configuration file for those events . Thank you again.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Aug 2021 22:19:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562326#M195571</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-05T22:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: Props Conf File</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562358#M195579</link>
      <description>&lt;P&gt;Can you post your current version?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 06:02:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562358#M195579</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-08-06T06:02:19Z</dc:date>
    </item>
    <item>
      <title>Re: Props Conf File</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562427#M195612</link>
      <description>&lt;P&gt;7.3.3&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 14:49:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562427#M195612</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-06T14:49:26Z</dc:date>
    </item>
    <item>
      <title>Re: Props Conf File</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562461#M195619</link>
      <description>I mean your props.conf and transforms.conf (if you have also it).</description>
      <pubDate>Fri, 06 Aug 2021 18:46:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562461#M195619</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-08-06T18:46:20Z</dc:date>
    </item>
    <item>
      <title>Re: Props Conf File</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562544#M195650</link>
      <description>&lt;P&gt;Why we need the version of it...? .....anyways, I solved that issue (see below). Thank you so much, appreciated!!!&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;SPAN&gt;SHOULD_LINEMERGE=false&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;SPAN&gt;LINE_BREAKER=([\r\n]+)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;SPAN&gt;NO_BINARY_CHECK=true&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;SPAN&gt;TIME_PREFIX=\,+\s&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;SPAN&gt;TIME_FORMAT=%d %b %Y %H:%M:%S %z&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&lt;SPAN&gt;MAX_TIMESTAMP_LOOKAHEAD=26&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 07:19:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562544#M195650</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-09T07:19:09Z</dc:date>
    </item>
    <item>
      <title>Re: Props Conf File</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562552#M195656</link>
      <description>&lt;P&gt;hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;,&lt;BR /&gt;&lt;BR /&gt;You have pipe-separated data, you can also try&amp;nbsp;&amp;nbsp;&lt;STRONG&gt;INDEXED_EXTRACTIONS&lt;/STRONG&gt;.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[sourcetype]
INDEXED_EXTRACTIONS = PSV
FIELD_NAMES = timestamp,context,type,log_level,code,message
TIMESTAMP_FIELDS = timestamp
SHOULD_LINEMERGE = false&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 08:04:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562552#M195656</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2021-08-09T08:04:29Z</dc:date>
    </item>
    <item>
      <title>Re: Props Conf File</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562615#M196046</link>
      <description>&lt;P&gt;.... yes working as expected. Thank you, truly&amp;nbsp; appreciated.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 14:39:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562615#M196046</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-09T14:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: Props Conf File</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562616#M196047</link>
      <description>&lt;P&gt;..yes working as expected.....thank you so much, truly appreciated!!!&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 14:41:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562616#M196047</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-09T14:41:39Z</dc:date>
    </item>
    <item>
      <title>Re: Props Conf File</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562619#M196048</link>
      <description>&lt;P&gt;Please accept it as a solution, so it will help others with similar issue.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 14:44:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Props-Conf-File/m-p/562619#M196048</guid>
      <dc:creator>manjunathmeti</dc:creator>
      <dc:date>2021-08-09T14:44:27Z</dc:date>
    </item>
  </channel>
</rss>

