Getting Data In

How to remove the header line from the log file so that data should be indexed without the header.


Below is my log file, i need to send log to my index without the header name and with only the values with there respective field name by using props.conf file

CHG0057654~^~9/10/2020 4:45:00 PM~^~9/10/2020 5:45:00 PM~^~Linux~^~BASF Linux Patching testing

can anyone tell us how to write props.conf file

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Dashboard Studio Challenge - Learn New Tricks, Showcase Your Skills, and Win Prizes!

Reimagine what you can do with your dashboards. Dashboard Studio is Splunk’s newest dashboard builder to ...

Introducing Edge Processor: Next Gen Data Transformation

We get it - not only can it take a lot of time, money and resources to get data into Splunk, but it also takes ...

Take the 2021 Splunk Career Survey for $50 in Amazon Cash

Help us learn about how Splunk has impacted your career by taking the 2021 Splunk Career Survey. Last year’s ...