Getting Data In

Is it possible to use two stanza specs in props.conf?

h3llocomputer
Explorer

I have a syslog server that collects all of my network device logs (routers, switches, etc) and I have a Universal Forward set up on this server to send all of these logs to Splunk Cloud. I have a new group of devices sending logs to this syslog server and I need to edit the timezone for these new devices (I cannot edit the timestamp at the source). I know that I will need to change my forward server on the UF and change it to my Heavy Forwarder since as far as I know, I can't do any timestamp parsing on the UF.

Would I be able to use multiple specs to in props.conf to enable me to single out these specific devices AND the specific sourcetype (since I'm using a wildcard in the host spec, I want to be sure I am only getting the "syslog:network" logs)? Example:

[host::CISCO_*] AND [syslog:network]
TZ = America/Chicago

Is this possible, or am I doomed to creating a stanza for each host device?

woodcock
Esteemed Legend

It is a little known fact that as of v6.6 Indexers will honor the TZ= setting as it exists on the UF in preference to anything that exists on the Indexer. So just use a sourcetype-based setting on the syslog-ng UF.

0 Karma

h3llocomputer
Explorer

Interesting. Would this setting live in props.conf on the UF or in some other file?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...