Getting Data In

Why aren't my apps props.conf not being exported when using export = system?

New Member

My props.conf values are not being picked up by the Splunk search app. I currently have the following stanza set in


access = read : [*], write : [admin]

export = system

My props.conf file looks like the following so far. I need the KV_MODE = none property to be picked up for my sourcetype.

KV_MODE = none

This works just fine when I put this in ./default/local. Can anyone tell me what I'm doing wrong so I can get this props.conf exported?


0 Karma


you need to add your custom config to 'local' folder of your app and not 'default'

eg /opt/splunk/etc/apps/your_app/local OR /opt/splunk/etc/apps/search/local for testing

0 Karma
Get Updates on the Splunk Community!

Security Highlights: September 2022 Newsletter

 September 2022 The Splunk App for Fraud Analytics (SFA) is now Splunk SupportedUse your existing Splunk ...

Platform Highlights | September 2022 Newsletter

 September 2022 What’s New in 9.0 and How to UpgradeGet a walk through of what is new Splunk Enterprise 9.0 ...

Observability Highlights | September 2022 Newsletter

 September 2022 Splunk Observability SuiteAccess to "Classic" SignalFx Interface Will be Removed on Sept 30, ...