Getting Data In

Why is the global sourcetype defined in props.conf and transforms.conf not used by my custom app?

faustf
Communicator

Hi guys

I've defined my sourcetype, transforms and lookup in /opt/splunk/etc/system/local/props.conf and /opt/splunk/etc/system/local/transforms.conf (I set the lookup from the web interface).
Everything is working fine with the default Search and Reporting App.
After I created my customApp and if I perform the same search in the App, I can see the right source_type associated to my data but the regex that I defined in /opt/splunk/etc/system/local/transforms.conf is not applied.

Any suggestion?

Thanks

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Most likely there's some config in the wrong place. Here's a start:

$SPLUNK_HOME/bin/splunk btool props list your_sourcetype --debug
$SPLUNK_HOME/bin/splunk btool transforms list your_transforms_or_lookup --debug

Check if all relevant settings are in the right place from Splunk's point of view. For more detailed help you'll need to share your config.

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Most likely there's some config in the wrong place. Here's a start:

$SPLUNK_HOME/bin/splunk btool props list your_sourcetype --debug
$SPLUNK_HOME/bin/splunk btool transforms list your_transforms_or_lookup --debug

Check if all relevant settings are in the right place from Splunk's point of view. For more detailed help you'll need to share your config.

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Feel free to elaborate what you did to fix and mark as accepted.

0 Karma

faustf
Communicator

Thanks, this helped!

0 Karma
Get Updates on the Splunk Community!

Uncovering Multi-Account Fraud with Splunk Banking Analytics

Last month, I met with a Senior Fraud Analyst at a nationally recognized bank to discuss their recent success ...

Secure Your Future: A Deep Dive into the Compliance and Security Enhancements for the ...

What has been announced?  In the blog, “Preparing your Splunk Environment for OpensSSL3,”we announced the ...

New This Month in Splunk Observability Cloud - Synthetic Monitoring updates, UI ...

This month, we’re delivering several platform, infrastructure, application and digital experience monitoring ...