Getting Data In

Is it possible to edit props.conf from Splunk Web?

gauravmishra15
Path Finder

Hi Friends,

I've added a custom application in SPLUNK which utilizes LINE_BREAKER and SHOULD_LINEMERGE features of props.conf. The implementation works great in my development instance of SPLUNK.

I have to create this application and add line merge logic on a Splunk Cloud instance. I need your help to understand:

Does SPLUNK offer a way to update application specific props.conf file (from Splunk Web) so that I can apply LINE_BREAKER and LINEMERGE logic? If yes, Please help me with the procedure or how can I achieve this if creating a file in Filesystem and editing is the only option.

MuS
Legend

Hi gauravmishra15,

a bit late for the party ...
In Splunk Enterprise under Settings - Source Types you can list, create and edit sourcetypes options in the according props.conf.

The docs talk about the process to modify sourcetypes in Splunk Enterprise here http://docs.splunk.com/Documentation/Splunk/latest/Data/Managesourcetypes and for Splunk Cloud here http://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Managesourcetypes

Hope this helps ...

cheers, MuS

amiracle
Splunk Employee
Splunk Employee

Check out this post, it shows how you can use the Web UI to modify the props.conf :
https://answers.splunk.com/answers/149597/im-struggling-with-how-i-should-be-doing-inputs-and-also-p...

I hope that helps!

-Kam

ichard
Engager

That link seems to have gone dead.

tuomassalo
Engager

The link just has one extra plus sign in the end. Can't seem to add a link here, but copy+paste this: https://answers.splunk.com/answers/149597/im-struggling-with-how-i-should-be-doing-inputs-and-also-p...

0 Karma

skoelpin
SplunkTrust
SplunkTrust

I'm pretty sure you CANNOT modify your props.conf from the UI. You will need to edit the .conf file on the indexer

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...