Dashboards & Visualizations

Configure line breaker

macadminrohit
Contributor

Hi,

I have splunk enterprise running on my system and forwarder and deployer are on same machine, I need to configure line breaker for events for few of the log files, to send one event per log file without breaking any log file in multiple events.

I know the regex to be used:

I know that the above configuration is to be made on the props.conf, I just need to know where this props.conf has to be deployed, on the forwarder or deployer?

And whats the best practice to do that??

Tags (1)
0 Karma

sundareshr
Legend

The props should ultimately end up on the indexer. If you are using a deployment server, It would be best to put this within an app on the deployment server and push it out to all your indexers.

Here is a good resource for future reference https://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F

0 Karma
Get Updates on the Splunk Community!

Splunk Search APIを使えば調査過程が残せます

   このゲストブログは、JCOM株式会社の情報セキュリティ本部・専任部長である渡辺慎太郎氏によって執筆されました。 Note: This article is published in both Japanese ...

Integrating Splunk Search API and Quarto to Create Reproducible Investigation ...

 Splunk is More Than Just the Web Console For Digital Forensics and Incident Response (DFIR) practitioners, ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...