Dashboards & Visualizations

Configure line breaker



I have splunk enterprise running on my system and forwarder and deployer are on same machine, I need to configure line breaker for events for few of the log files, to send one event per log file without breaking any log file in multiple events.

I know the regex to be used:

I know that the above configuration is to be made on the props.conf, I just need to know where this props.conf has to be deployed, on the forwarder or deployer?

And whats the best practice to do that??

Tags (1)
0 Karma


The props should ultimately end up on the indexer. If you are using a deployment server, It would be best to put this within an app on the deployment server and push it out to all your indexers.

Here is a good resource for future reference https://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F

0 Karma
Did you miss .conf21 Virtual?

Good news! The event's keynotes and many of its breakout sessions are now available online, and still totally FREE!