I want to be able to edit this file /opt/splunk/etc/system/default/props.conf and add this data input:
KVMODE = json
MAXTIMESTAMPLOOKAHEAD = 10
NOBINARYCHECK = 1
SHOULDLINEMERGE = false
TIMEFORMAT = %s
TIMEPREFIX = \"_REALTIMETIMESTAMP\" : \"
pulldown_type = 1
I don't see any way to do it with SPLUNK_CMD
Also didn't find any documentation in https://hub.docker.com/r/splunk/splunk/
Not too familiar with the Docker approach, but in general, you should never, ever edit any config file in etc/system/default/.
Put the additional input configuration into a dedicated app, which you place in etc/apps/.
Oh, didn't even spot that, but this kind of props.conf all goes onto the indexer (unless you use a heavy forwarder). I was a bit blinded by your "I want to ... add this data input". Inputs are usually defined in inputs.conf not props.conf.
I'm using Splunk Cloud and when add new source type called journald in the Splunk cloud it's not working unless I'm updating the UF as well with
[journald] KV_MODE = json MAX_TIMESTAMP_LOOKAHEAD = 10 NO_BINARY_CHECK = 1 SHOULD_LINEMERGE = false TIME_FORMAT = %s TIME_PREFIX = \"__REALTIME_TIMESTAMP\" : \" pulldown_type = 1 TZ=UTC
Is there any option to change it on the Splunk cloud only ?? and it will take effect?