Getting Data In

Does the UF use props.conf and/or transforms.conf or not?

nisse
Explorer

If I am reading http://splunk-base.splunk.com/answers/27373/universal-forwarder-and-propsconf-and-transformsconf correctly, the UF does not support props.conf and transforms.conf. Yet the RPM includes the props files, which I find extremely confusing. What's the correct story? Is props.conf useful without transforms.conf? Which, if either, actually works with the UF?

$ rpm -qa | grep splunk
splunkforwarder-4.2.2-101277

$ rpm -ql splunkforwarder| egrep 'props|transforms' | sort
/opt/splunkforwarder/etc/apps/SplunkUniversalForwarder/default/props.conf
/opt/splunkforwarder/etc/apps/search/default/props.conf
/opt/splunkforwarder/etc/system/README/props.conf.example
/opt/splunkforwarder/etc/system/README/props.conf.spec
/opt/splunkforwarder/etc/system/default/props.conf

Tags (1)

gkanapathy
Splunk Employee
Splunk Employee

You have misread. The UF does "support" props.conf. However, most settings in that file are irrelevant on a universal forwarder: http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F

Additionally, there are many settings in props.conf that do not reference transforms.conf. In fact, only REPORT, TRANSFORM, and LOOKUP do.

nisse
Explorer

Thank you for clarifying!

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...