<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PROPS configuration for Source Data with Field Names and Values Stored in Text File in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/PROPS-configuration-for-Source-Data-with-Field-Names-and-Values/m-p/568862#M198265</link>
    <description>&lt;P&gt;It would help if you explained what you mean by "it's not working".&lt;/P&gt;&lt;P&gt;The TIMESTAMP_FIELDS setting is for use with INDEXED_EXTRACTIONS.&amp;nbsp; Try these settings&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[ __auto__learned__ ]
SHOULD_LINEMERGE = false
LINE_BREAKER = ([\r\n]+)
TIME_PREFIX = \{"timeStamp":"
TIME_FORMAT = %Y-%m-%d %H:%M:%S %Z
MAX_TIMESTAMP_LOOKAHEAD = 29&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 29 Sep 2021 00:30:47 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2021-09-29T00:30:47Z</dc:date>
    <item>
      <title>PROPS configuration for Source Data with Field Names and Values Stored in Text File</title>
      <link>https://community.splunk.com/t5/Splunk-Search/PROPS-configuration-for-Source-Data-with-Field-Names-and-Values/m-p/568789#M198225</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I have some issues writing a PROPS configuration file for the following&amp;nbsp; source&amp;nbsp;data stored in text file. I&amp;nbsp; also used &lt;STRONG&gt;TIMESTAMP_FIELDS=&amp;nbsp;timeStamp &lt;/STRONG&gt;there&lt;STRONG&gt;, &lt;/STRONG&gt;to have field values under field names&lt;STRONG&gt;.&amp;nbsp;&lt;/STRONG&gt; But, it's not working. My PROPS configuration and a sample event are given below.&amp;nbsp; Any help will be highly appreciated. Thank you so much.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;[ __auto__learned__ ]&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;SHOULD_LINEMERGE=false&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;LINE_BREAKER=([\r\n]+)&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;TIMESTAMP_FIELDS=timeStamp&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;TIME_PREFIX =^\{\"timeStamp\"\:\"&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;TIME_FORMAT=%Y-%m-%d %H:%M:%S&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;MAX_TIMESTAMP_LOOKAHEAD=29&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;{"timeStamp":"2021-06-21 14:53:56 EDT","appName":"OSD","userType":"FILTER","StatCd":null,"Amt":null,"errorMsg":"","eventId":"APP_ENTRY","eventType":"VIEW","fileSourceCd":null,"ipAddr":"11.212.41.151","mftCd":null,"outputCd":null,"planNum":null,"reasonCd":null,"returnCd":"00","sessionId":"XWGMwkncVD0m60OQBOahu8s/qG1c=","Period":null,"cat":"234207501","Type":null,"userId":"cdabea740a-g9a0-408f-a6a7-5ae70c689e6d","vsardata":{"uri":"/osd/rest/accountSummary","host":"appsa.rup.afsiep.net","ipAddress":"11.212.41.151","Id":"AXSabea753c-d9a0-408f-a6a7-5ae70c689e6d","requestId":"as58510cd-0459-614b7bc4-1afdd700-0bf875285d76","referer":&lt;A href="https://saada.ruer.egsiep.net/osd/" target="_blank" rel="noopener noreferrer"&gt;https://saada.ruer.egsiep.net/osd/&lt;/A&gt;,"responseStatus":0}}&lt;/P&gt;&lt;P class="x_MsoNormal"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Sep 2021 16:12:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/PROPS-configuration-for-Source-Data-with-Field-Names-and-Values/m-p/568789#M198225</guid>
      <dc:creator>SplunkDash</dc:creator>
      <dc:date>2021-09-28T16:12:43Z</dc:date>
    </item>
    <item>
      <title>Re: PROPS configuration for Source Data with Field Names and Values Stored in Text File</title>
      <link>https://community.splunk.com/t5/Splunk-Search/PROPS-configuration-for-Source-Data-with-Field-Names-and-Values/m-p/568862#M198265</link>
      <description>&lt;P&gt;It would help if you explained what you mean by "it's not working".&lt;/P&gt;&lt;P&gt;The TIMESTAMP_FIELDS setting is for use with INDEXED_EXTRACTIONS.&amp;nbsp; Try these settings&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[ __auto__learned__ ]
SHOULD_LINEMERGE = false
LINE_BREAKER = ([\r\n]+)
TIME_PREFIX = \{"timeStamp":"
TIME_FORMAT = %Y-%m-%d %H:%M:%S %Z
MAX_TIMESTAMP_LOOKAHEAD = 29&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 29 Sep 2021 00:30:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/PROPS-configuration-for-Source-Data-with-Field-Names-and-Values/m-p/568862#M198265</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2021-09-29T00:30:47Z</dc:date>
    </item>
  </channel>
</rss>

