Splunk Dev

Break reports

derekclarke
New Member

I am importing logfiles into Splunk from a file. Each log entry starts with the string "** Alert" and ends with a double paragraph mark. The log entries are multi-line and of variable length, and a combination of various sources (windows alerts, firewall alerts etc).

When importing, I click 'A file or directory of files'; 'Consume any file on this Splunk server'; 'Upload and index a file'; then browse for the file and click save.

No matter what I try in props.conf, each log entry begins with the date (which is the SECOND line of the entry) and ends with the "** Alert" from the next extry. I am editing the [default] section. (I have copied props.conf from /etc/system/default into etc/system/local and this is the one I'm editing).

Can someone suggest a suitible setting in props.conf or is it that I have to do something to make Splunk use the default part of props.conf rather than making its own mind up about what sort of file it's importing?

TIA

Tags (1)
0 Karma

derekclarke
New Member

Damn - I didn't stop and restart the daemon. Idiot.

Ignore please - works fine now!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...