Getting Data In

Is crcSalt = still supported?

ontai
Explorer

I'm trying to index Nessus and Snort rules for use in cross-correlation of security events. In previous versions of Splunk, I had to add an entry in props.conf (crcSalt = ) to ensure that Splunk would reindex the entire file any time the contents changed.

But now when I startup Splunk running 4.3.1, I get errors about a potential syntax error:

Possible typo in stanza [nessus_plugins] in /opt/splunk/etc/apps/ResponsysSecurityConsole/local/props.conf, line 5: crcSalt =

Is this option still supported? If not, what can I do to ensure that Splunk always indexes the complete file when any changes to it are detected?

Thx.

Craig

Tags (2)
0 Karma
1 Solution

sdaniels
Splunk Employee
Splunk Employee

Should be fine. I believe it's crcSalt = <SOURCE>. Needs to be capitilized. And you would put it in inputs.conf.

View solution in original post

sdaniels
Splunk Employee
Splunk Employee

Should be fine. I believe it's crcSalt = <SOURCE>. Needs to be capitilized. And you would put it in inputs.conf.

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...