Splunk Search

How to edit props.conf to specify a different regex for each of three sourcetypes?

minkyuk
Explorer

Hello,

I'm trying to parse three different log files with different regex.

I have three different sourcetypes for each, and I'm wondering how I can specify a different regex for each on props.conf.

Would it be as simple as

[sourcetype_one] 
BREAK_ONLY_BEFORE= <regex>
[sourcetype_two]
...

Thank you, I would appreciate your ideas
Jack

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, it could be as simple as that. It's difficult to say for sure without seeing samples of your data.

---
If this reply helps you, Karma would be appreciated.
0 Karma

jnussbaum_splun
Splunk Employee
Splunk Employee

The sourcetypes that you define in inputs.conf can be called out in stanzas in your props.conf, as you've mentioned above.

0 Karma

woodcock
Esteemed Legend

Correct, you make a stanza for each and in the stanza header you put one sourcetype, just like you showed in your question.

0 Karma
Get Updates on the Splunk Community!

Splunk App for Anomaly Detection End of Life Announcment

Q: What is happening to the Splunk App for Anomaly Detection?A: Splunk is officially announcing the ...

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...