Getting Data In

Is it possible to edit props.conf from Splunk Web?

gauravmishra15
Path Finder

Hi Friends,

I've added a custom application in SPLUNK which utilizes LINE_BREAKER and SHOULD_LINEMERGE features of props.conf. The implementation works great in my development instance of SPLUNK.

I have to create this application and add line merge logic on a Splunk Cloud instance. I need your help to understand:

Does SPLUNK offer a way to update application specific props.conf file (from Splunk Web) so that I can apply LINE_BREAKER and LINEMERGE logic? If yes, Please help me with the procedure or how can I achieve this if creating a file in Filesystem and editing is the only option.

MuS
SplunkTrust
SplunkTrust

Hi gauravmishra15,

a bit late for the party ...
In Splunk Enterprise under Settings - Source Types you can list, create and edit sourcetypes options in the according props.conf.

The docs talk about the process to modify sourcetypes in Splunk Enterprise here http://docs.splunk.com/Documentation/Splunk/latest/Data/Managesourcetypes and for Splunk Cloud here http://docs.splunk.com/Documentation/SplunkCloud/latest/Data/Managesourcetypes

Hope this helps ...

cheers, MuS

amiracle
Splunk Employee
Splunk Employee

Check out this post, it shows how you can use the Web UI to modify the props.conf :
https://answers.splunk.com/answers/149597/im-struggling-with-how-i-should-be-doing-inputs-and-also-p...

I hope that helps!

-Kam

ichard
Engager

That link seems to have gone dead.

tuomassalo
Engager

The link just has one extra plus sign in the end. Can't seem to add a link here, but copy+paste this: https://answers.splunk.com/answers/149597/im-struggling-with-how-i-should-be-doing-inputs-and-also-p...

0 Karma

skoelpin
SplunkTrust
SplunkTrust

I'm pretty sure you CANNOT modify your props.conf from the UI. You will need to edit the .conf file on the indexer

0 Karma
Get Updates on the Splunk Community!

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through: An introduction to the Splunk Threat ...