Getting Data In

Why aren't my apps props.conf not being exported when using export = system?

inmanx09
New Member

My props.conf values are not being picked up by the Splunk search app. I currently have the following stanza set in

$SPLUNK_HOME/etc/apps//metadata

[]
access = read : [*], write : [admin]

[props]
export = system

My props.conf file looks like the following so far. I need the KV_MODE = none property to be picked up for my sourcetype.

[my_type]
KV_MODE = none

This works just fine when I put this in ./default/local. Can anyone tell me what I'm doing wrong so I can get this props.conf exported?

Thanks.

0 Karma

lakshman239
Influencer

you need to add your custom config to 'local' folder of your app and not 'default'

eg /opt/splunk/etc/apps/your_app/local OR /opt/splunk/etc/apps/search/local for testing

0 Karma
Get Updates on the Splunk Community!

Splunk Observability Synthetic Monitoring - Resolved Incident on Detector Alerts

We’ve discovered a bug that affected the auto-clear of Synthetic Detectors in the Splunk Synthetic Monitoring ...

Video | Tom’s Smartness Journey Continues

Remember Splunk Community member Tom Kopchak? If you caught the first episode of our Smartness interview ...

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud?

3-2-1 Go! How Fast Can You Debug Microservices with Observability Cloud? Learn how unique features like ...