Getting Data In

Restoring Default Configuration for aws:s3 Sourcetype in Splunk

Rahul_a
Explorer

In Splunk, I added an AWS add-on and tried to get data from AWS S3. While creating the input, it took the sourcetype as aws:s3:csv by default, and I was receiving the data properly. However, I accidentally changed the configuration for the aws:s3:csv sourcetype, and now the logs are not being received correctly. Can anyone help me by providing the default configuration for this sourcetype?"

0 Karma

richgalloway
SplunkTrust
SplunkTrust

You should be able to remove your local changes by deleting local/props.conf from the AWS add-on directory and restarting Splunk.  If you changed default/props.conf (never advised) then re-installing the add-on will restore the defaults.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...