Getting Data In

Index list type data using props.conf

New Member


I have a sever with splunk enterprise installed to monitor a directory containing <sample-filename>.gz files

Each file is of the below format and need to create a sourcetype that can 

1. Ignore lines staring with //

2. Map the vales in [ ] to a standard header


[1599249608,75972,"",638744076,1,861,337,3,"9","http",80,388951746,"",0,"","","","empty","Sample Filtering","","","GET",21,3,126]

// random info here

// something something random


Tried various strategies but filed. Looking for you help.


0 Karma

Super Champion

provide field header.

If this helps, give a like below.
0 Karma
Get Updates on the Splunk Community!

The Splunk Success Framework: Your Guide to Successful Splunk Implementations

Splunk Lantern is a customer success center that provides advice from Splunk experts on valuable data ...

Splunk Training for All: Meet Aspiring Cybersecurity Analyst, Marc Alicea

Splunk Education believes in the value of training and certification in today’s rapidly-changing data-driven ...

Investigate Security and Threat Detection with VirusTotal and Splunk Integration

As security threats and their complexities surge, security analysts deal with increased challenges and ...