Getting Data In

Specific props.conf stanza type and supporting documentation?

pkeller
Contributor

I've noticed in another Splunk environment at my site that they've set up what appear to be undocumented stanzas in props.conf

[foo:BAR]
REPORT-fooregex0=fooregex0

assume that foo is the sourcetype and BAR is a pattern in an event logged in the 'foo' sourcetype.

In the props.conf spec and example, and in numerous web searches I have failed to find a reference to this stanza type ...

Can someone give me some insight or point to some documentation on it?

Thanks very much.

Tags (2)
0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Is that the exact spelling save for foo and BAR being changed? Then I'd guess the sourcetype actually is called foo:BAR.

JoeSco27
Communicator
0 Karma
Get Updates on the Splunk Community!

Automatic Discovery Part 1: What is Automatic Discovery in Splunk Observability Cloud ...

If you’ve ever deployed a new database cluster, spun up a caching layer, or added a load balancer, you know it ...

Real-Time Fraud Detection: How Splunk Dashboards Protect Financial Institutions

Financial fraud isn't slowing down. If anything, it's getting more sophisticated. Account takeovers, credit ...

Splunk + ThousandEyes: Correlate frontend, app, and network data to troubleshoot ...

 Are you tired of troubleshooting delays caused by siloed frontend, application, and network data? We've got a ...