<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PROF Conf Issues in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/PROF-Conf-Issues/m-p/563116#M196196</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How are you onboarding this data?&lt;/P&gt;&lt;P&gt;If you are onboarding this data from a remote server using UF, you should place the props.conf on the remote server to extract the fields.&lt;/P&gt;&lt;P&gt;Its always better to test the extraction using UI i.e. settings -&amp;gt; Add Data -&amp;gt; upload -&amp;gt; choose psv as sourcetype. Once you are ok with extraction, copy the parameters deploy it over to the UF.&lt;/P&gt;&lt;P&gt;If this psv file does not has a header file, you need to mention the fields as well in the props.conf.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-- Hope this helps.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Aug 2021 19:33:17 GMT</pubDate>
    <dc:creator>anilchaithu</dc:creator>
    <dc:date>2021-08-12T19:33:17Z</dc:date>
    <item>
      <title>PROF Conf Issues</title>
      <link>https://community.splunk.com/t5/Splunk-Search/PROF-Conf-Issues/m-p/563106#M196193</link>
      <description>&lt;P&gt;Hello, I was trying to write PROPS configuration file following sample events...&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2021-06-08T13:26:53.665000-04:00|PGM|mtb1120ppcdwap6|vggtb|26462|&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;2021-06-08T13:26:54.478000-04:00|PGM|mtb1120ppcdwap6|vggtb|26462|&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;since it has pipe "|"..here is what I wrote..but not working... Any help will be highly appreciated...thank you so much..&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;SHOULD_LINEMERGE = false&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;LINE_BREAKER = ([\r\n]+)&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;INDEXED_EXTRACTIONS = psv&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;TIME_FORMAT = %Y%m%d %H:%M:%S:%Q&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;TIMESTAMP_FIELDS = TIMESTAMP&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 17:27:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/PROF-Conf-Issues/m-p/563106#M196193</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-08-12T17:27:11Z</dc:date>
    </item>
    <item>
      <title>Re: PROF Conf Issues</title>
      <link>https://community.splunk.com/t5/Splunk-Search/PROF-Conf-Issues/m-p/563116#M196196</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/234909"&gt;@SplunkDash&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How are you onboarding this data?&lt;/P&gt;&lt;P&gt;If you are onboarding this data from a remote server using UF, you should place the props.conf on the remote server to extract the fields.&lt;/P&gt;&lt;P&gt;Its always better to test the extraction using UI i.e. settings -&amp;gt; Add Data -&amp;gt; upload -&amp;gt; choose psv as sourcetype. Once you are ok with extraction, copy the parameters deploy it over to the UF.&lt;/P&gt;&lt;P&gt;If this psv file does not has a header file, you need to mention the fields as well in the props.conf.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-- Hope this helps.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 19:33:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/PROF-Conf-Issues/m-p/563116#M196196</guid>
      <dc:creator>anilchaithu</dc:creator>
      <dc:date>2021-08-12T19:33:17Z</dc:date>
    </item>
  </channel>
</rss>

