Archive

Is there a way to write a splunk query which displays our props.conf , transform.conf , indexes.conf configuarion as outputs

New Member

I would like to see in props.conf how data parsing is done

My query should return results stating

sourcetype TIMEFORMAT LINEBREAKER TIME_PREFIX etc

Tags (1)
0 Karma

SplunkTrust
SplunkTrust

hi nasamajh09,
here is a rest query that brings all props data: | rest /services/configs/conf-props
now you can filter, for example: | table title eai:appName eai:userName eai:acl.sharing TIME_FORMAT LINE_BREAKER TIME_PREFIX

hope it helps

0 Karma

SplunkTrust
SplunkTrust

also, same goes for indexes and transforms so:
| rest /services/configs/conf-indexes
| rest /services/configs/conf-transforms
and then filter however you like

0 Karma