<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help with props.conf changes in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208274#M60730</link>
    <description>&lt;P&gt;hello  ngatchasandra,&lt;/P&gt;

&lt;P&gt;The problem is not with roles or permissions it is with the props configurations which need to be done&lt;/P&gt;</description>
    <pubDate>Tue, 23 Feb 2016 17:32:44 GMT</pubDate>
    <dc:creator>vrmandadi</dc:creator>
    <dc:date>2016-02-23T17:32:44Z</dc:date>
    <item>
      <title>Help with props.conf changes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208267#M60723</link>
      <description>&lt;P&gt;&lt;A href="https://answers.splunk.comstorage/temp/106260-abc.txt"&gt;link text&lt;/A&gt;Hello Experts,&lt;/P&gt;

&lt;P&gt;Attached is the sample JSON file which I am trying to upload to Splunk.I have uploaded it by Splunk WEB and it broke the events successfully but when I am trying to upload via CLI it is taking all 8 events into a single event.Can you please help how to break those events(8).&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 17:37:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208267#M60723</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2016-02-18T17:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: Help with props.conf changes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208268#M60724</link>
      <description>&lt;P&gt;what version SPLUNK that use?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 17:46:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208268#M60724</guid>
      <dc:creator>gyslainlatsa</dc:creator>
      <dc:date>2016-02-18T17:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: Help with props.conf changes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208269#M60725</link>
      <description>&lt;P&gt;Are you using the correct time-range ( check the timestamp of the events in your file)? What is the retention period of the new index you created and are timestamp of events in your file older than the retention period?&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 17:55:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208269#M60725</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-02-18T17:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: Help with props.conf changes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208270#M60726</link>
      <description>&lt;P&gt;version 6.2.3 &lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 17:57:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208270#M60726</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2016-02-18T17:57:16Z</dc:date>
    </item>
    <item>
      <title>Re: Help with props.conf changes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208271#M60727</link>
      <description>&lt;P&gt;I have selected the time stamp as auto, when tried using CLI it is taking the file but it is not breaking into events..so can we use the same props from splunk web in the CLI  props file&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 17:58:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208271#M60727</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2016-02-18T17:58:58Z</dc:date>
    </item>
    <item>
      <title>Re: Help with props.conf changes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208272#M60728</link>
      <description>&lt;P&gt;did you select the indexes when loading the file?&lt;BR /&gt;
if so, try to post me a sample of your data here, I also try to indexing.&lt;/P&gt;</description>
      <pubDate>Thu, 18 Feb 2016 18:06:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208272#M60728</guid>
      <dc:creator>gyslainlatsa</dc:creator>
      <dc:date>2016-02-18T18:06:32Z</dc:date>
    </item>
    <item>
      <title>Re: Help with props.conf changes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208273#M60729</link>
      <description>&lt;P&gt;Hi  vrmandadi,&lt;/P&gt;

&lt;P&gt;Try to verify if your role have not the search restrictions  and see explanation to monitor this by follow the link:&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/6.2.1/Security/Addandeditroles"&gt;http://docs.splunk.com/Documentation/Splunk/6.2.1/Security/Addandeditroles&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2016 10:47:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208273#M60729</guid>
      <dc:creator>ngatchasandra</dc:creator>
      <dc:date>2016-02-23T10:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: Help with props.conf changes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208274#M60730</link>
      <description>&lt;P&gt;hello  ngatchasandra,&lt;/P&gt;

&lt;P&gt;The problem is not with roles or permissions it is with the props configurations which need to be done&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2016 17:32:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208274#M60730</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2016-02-23T17:32:44Z</dc:date>
    </item>
    <item>
      <title>Re: Help with props.conf changes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208275#M60731</link>
      <description>&lt;P&gt;Hello somesh,&lt;/P&gt;

&lt;P&gt;I am new to splunk what exactly does retention period mean?&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2016 17:35:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208275#M60731</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2016-02-23T17:35:21Z</dc:date>
    </item>
    <item>
      <title>Re: Help with props.conf changes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208276#M60732</link>
      <description>&lt;P&gt;I have attached the sample file,can you please try and let me know the props configuration in CLI..Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2016 20:49:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208276#M60732</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2016-02-23T20:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: Help with props.conf changes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208277#M60733</link>
      <description>&lt;P&gt;Hey Vineeth,&lt;/P&gt;

&lt;P&gt;Please ignore my comments, seems like I posted my comments of some other post here. &lt;/P&gt;

&lt;P&gt;You said you're able to successfully update and break events from Splunk Web. so you must've selected some sourcetype for it. Did you use the same sourcetype when you tried to upload it from CLI?? I'm guessing you used &lt;CODE&gt;splunk add oneshot&lt;/CODE&gt; method.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Feb 2016 21:22:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208277#M60733</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-02-23T21:22:36Z</dc:date>
    </item>
    <item>
      <title>Re: Help with props.conf changes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208278#M60734</link>
      <description>&lt;P&gt;You can use this for your sourcetype definition in props.conf (on Indexer/Heavy forwarder). Do remember to restart/reload splunk instance after making this change. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[ YourSourceType ]
SHOULD_LINEMERGE=false
NO_BINARY_CHECK=true
LINE_BREAKER=([\r\n]+)\{\"TRL_ID
TIME_FORMAT=%Y-%m-%d %H:%M:%S.%N %z
TIME_PREFIX=TRL_DATETIME_LOCAL_TXN\":\"
MAX_TIMESTAMP_LOOKAHEAD=30
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I've used TRL_DATETIME_LOCAL_TXN as the event timestamp field. Change as per your requirement.&lt;/P&gt;

&lt;P&gt;Once you've this setup, you can upload a file from CLI like this&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;splunk add oneshot fullpathtothefiletobeuploaded -index nameofindex -sourcetype sourcetypecreatedabove 
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 29 Sep 2020 08:54:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208278#M60734</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2020-09-29T08:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: Help with props.conf changes</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208279#M60735</link>
      <description>&lt;P&gt;Somesh Thank You so much will try this and let you know&lt;/P&gt;</description>
      <pubDate>Wed, 24 Feb 2016 04:42:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Help-with-props-conf-changes/m-p/208279#M60735</guid>
      <dc:creator>vrmandadi</dc:creator>
      <dc:date>2016-02-24T04:42:20Z</dc:date>
    </item>
  </channel>
</rss>

