Deployment Architecture

How do you override a default app setting on a search head cluster?

john_dagostino
Path Finder

We are using the Palo Alto TA and pushing the default app to our search head cluster. In props.conf there is an automatic lookup which references a KV store that is empty, causing errors when searching that data source on the search heads:

LOOKUP-minemeldfeeds_src_lookup = minemeldfeeds_lookup indicator AS src_ip OUTPUT value.autofocus_tags AS src_autofocus_tags

I've tried creating the same stanza in local/props.conf on the deployer without specifying the lookup but that just brings additional errors:

LOOKUP-minemeldfeeds_src_lookup =

We don't plan on using the minemeldfeeds so I don't see a need for this automatic lookup. Other than remarking the line in default, how would we disable a default setting in an app on the search heads?

0 Karma

lakshman239
Influencer

whats your version of splunk core, ES, CIM and PA add-on? we are on 7.0.3/ 5.0.x, 4.11.0 and 6.0.2 and don't use mimemeldfeeds and I don't see any error when searching sourcetype=pan:threat.

What error are you seeing? what's your search?

you may be able to override the default/transforms.conf def with local/transforms definition, but thats' normally not needed.

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...