Getting Data In

Specific props.conf stanza type and supporting documentation?

pkeller
Contributor

I've noticed in another Splunk environment at my site that they've set up what appear to be undocumented stanzas in props.conf

[foo:BAR]
REPORT-fooregex0=fooregex0

assume that foo is the sourcetype and BAR is a pattern in an event logged in the 'foo' sourcetype.

In the props.conf spec and example, and in numerous web searches I have failed to find a reference to this stanza type ...

Can someone give me some insight or point to some documentation on it?

Thanks very much.

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Is that the exact spelling save for foo and BAR being changed? Then I'd guess the sourcetype actually is called foo:BAR.

JoeSco27
Communicator
0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...