Getting Data In

Why props.conf not getting picked up while ingesting data through HEC, /event endpoint?

neha898
New Member

Why props.conf not getting picked up while ingesting data through HEC, /event endpoint?

0 Karma
1 Solution

starcher
Influencer

Only raw gets sent through the parsing queue. Using event presumes you are properly formatting your event in JSON and the JSON extraction handles everything. This is expected behavior.

View solution in original post

starcher
Influencer

Only raw gets sent through the parsing queue. Using event presumes you are properly formatting your event in JSON and the JSON extraction handles everything. This is expected behavior.

neha898
New Member

I guess this is the confirmation I was looking for, so docker container logs should be ingested into SPlunk via the raw endpoint if we want to parse them at Splunk end.

0 Karma

starcher
Influencer

keep in mind search time extractions are different than say even breaking and time stamping at the HF where HEC runs. so for the HF yes that is as I said and you'd need to be on raw.

0 Karma

neha898
New Member

Thanks a lot @starcher

0 Karma

xavierashe
Contributor

Let me ask a clairifying question. Are you collecting event through a HEC input on a heavy fowarder, and it doesn't seem to apply your props config? Can you post a sample event and your props.conf?

0 Karma

neha898
New Member

Yes, I am trying to collect events via HEC. Splunk is smartly formatting the timestamp, issue is that each exception form docker is getting posted as a separate event on a new line preceded by a containerid. My main doubt is that does props.conf on HF get picked up for HEC collector/event endpoint? I read on my other answers on this forum that /event endpoint doesn't pickup props and transforms processing.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...