Getting Data In

How to reset 'props.conf' to defaults w/o reinstalling Splunk?

timfrostmann
Engager

Hi all,

I have Splunk on Windows 10.
I fiddled recently with some properties in "C:\Program Files\Splunk\etc/system/default/props.conf" but later I restored them to defaults (or so I thought. I might well forget to reset some changes)
Now I have a problem with "File Integrity Check": "props.conf" 's Check result is "differs"

I'd like to reset the file to defaults, desirably w/o reinstalling Splunk but maybe I should just ignore the notification?

Many thanks,
Tim

0 Karma
1 Solution

hardikJsheth
Motivator

Download tar file of the splunk version that you are using and then copy past props.conf file from the same location of the extracted tar.
https://www.splunk.com/en_us/download/splunk-enterprise.html

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

Now you know why the top of the file has a warning about not modifying the file.
Had you made your changes to $SPLUNK_HOME\etc\system\local\props.conf you could have returned to the default settings by deleting local\props.conf.

---
If this reply helps you, Karma would be appreciated.

hardikJsheth
Motivator

Download tar file of the splunk version that you are using and then copy past props.conf file from the same location of the extracted tar.
https://www.splunk.com/en_us/download/splunk-enterprise.html

Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...