Getting Data In

Splunk 4.2 complains about possible typo for CLEAN_KEYS

SplunkTrust
SplunkTrust

Upon an upgrade to 4.2 I noticed that splunk spit out the following:

Possible typo in stanza [source::/tmp/test.csv] in /opt/splunk/etc/system/local/props.conf, line 16: CLEAN_KEYS  =  false
        Did you mean 'CHARSET'?
        Did you mean 'CHECK_FOR_HEADER'?
        Did you mean 'CHECK_METHOD'?
        Did you mean 'Conversely, if you commonly search a large event set with expressions like company_id!'?

Did CLEAN_KEYS get phased out of Splunk 4.2? I don't see any mention of it anywhere...

Thanks, Josh

Tags (2)
0 Karma
1 Solution

Builder

CLEAN_KEYS is actually a transforms.conf setting, not props.conf. This is why config checker is barking. It's not actually a typo, but an invalid setting for props.conf. http://www.splunk.com/base/Documentation/latest/Admin/Transformsconf

View solution in original post

Builder

CLEAN_KEYS is actually a transforms.conf setting, not props.conf. This is why config checker is barking. It's not actually a typo, but an invalid setting for props.conf. http://www.splunk.com/base/Documentation/latest/Admin/Transformsconf

View solution in original post

SplunkTrust
SplunkTrust

Ah shoot, you are right, that's my bad. Thanks for pointing out my oversight!

0 Karma