Archive2

Are attributes in Splunk .conf files case sensitive?

Splunk Employee
Splunk Employee

Does Splunk care whether or not my configuration files have uppercase or lowercase attributes? I'm seeing odd behavior when my setting sourcetypes in my inputs.conf.

This didn't seem to work properly:

[monitor://C:\Windows\Logs\MyApp\]
SOURCETYPE = my_app

This works fine:

[monitor://C:\Windows\Logs\MyApp\]
sourcetype = my_app
Tags (1)
1 Solution

Splunk Employee
Splunk Employee

Yes, all attributes are case sensitive. Pay close attention to the config file specs and documentation.

A few examples:

inputs.conf

[monitor://C:\Windows\Logs\MyApp\]
sourcetype = my_app
host = myserver.splunk.com
followTail = true

props.conf

[my_app]
REPORT-somename = extract_something
SHOULD_LINEMERGE = false
maxDist = 350

fields.conf

[my_app]
INDEXED_VALUE = false

View solution in original post

Splunk Employee
Splunk Employee

Yes, all attributes are case sensitive. Pay close attention to the config file specs and documentation.

A few examples:

inputs.conf

[monitor://C:\Windows\Logs\MyApp\]
sourcetype = my_app
host = myserver.splunk.com
followTail = true

props.conf

[my_app]
REPORT-somename = extract_something
SHOULD_LINEMERGE = false
maxDist = 350

fields.conf

[my_app]
INDEXED_VALUE = false

View solution in original post