Splunk Dev

Break reports

derekclarke
New Member

I am importing logfiles into Splunk from a file. Each log entry starts with the string "** Alert" and ends with a double paragraph mark. The log entries are multi-line and of variable length, and a combination of various sources (windows alerts, firewall alerts etc).

When importing, I click 'A file or directory of files'; 'Consume any file on this Splunk server'; 'Upload and index a file'; then browse for the file and click save.

No matter what I try in props.conf, each log entry begins with the date (which is the SECOND line of the entry) and ends with the "** Alert" from the next extry. I am editing the [default] section. (I have copied props.conf from /etc/system/default into etc/system/local and this is the one I'm editing).

Can someone suggest a suitible setting in props.conf or is it that I have to do something to make Splunk use the default part of props.conf rather than making its own mind up about what sort of file it's importing?

TIA

Tags (1)
0 Karma

derekclarke
New Member

Damn - I didn't stop and restart the daemon. Idiot.

Ignore please - works fine now!

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...