Hi,
if I import data from a single file, can I get any information of the stanzas (of the several props.conf) splunk uses for indexing to research some strange behaviour in event-breaking while indexing?
There are too much stanzas in S.o.S. to search by hand.
best regards
Marco
No, I don't think this information is logged by default. I would recommend btool (either on the command line or I think SoS comes with a version you can run from the search bar) to look at the host / source / sourcetype and get the full list of properties applied.
Remember, if you're forcing source / sourcetype / host etc, the only stanzas that will apply are the ones that match the values the events had when they entered the parsing process.