Splunk Search

How to edit props.conf to specify a different regex for each of three sourcetypes?

minkyuk
Explorer

Hello,

I'm trying to parse three different log files with different regex.

I have three different sourcetypes for each, and I'm wondering how I can specify a different regex for each on props.conf.

Would it be as simple as

[sourcetype_one] 
BREAK_ONLY_BEFORE= <regex>
[sourcetype_two]
...

Thank you, I would appreciate your ideas
Jack

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes, it could be as simple as that. It's difficult to say for sure without seeing samples of your data.

---
If this reply helps you, Karma would be appreciated.
0 Karma

jnussbaum_splun
Splunk Employee
Splunk Employee

The sourcetypes that you define in inputs.conf can be called out in stanzas in your props.conf, as you've mentioned above.

0 Karma

woodcock
Esteemed Legend

Correct, you make a stanza for each and in the stanza header you put one sourcetype, just like you showed in your question.

0 Karma
Get Updates on the Splunk Community!

Your Guide to Splunk Digital Experience Monitoring

A flawless digital experience isn't just an advantage, it's key to customer loyalty and business success. But ...

Data Management Digest – November 2025

  Welcome to the inaugural edition of Data Management Digest! As your trusted partner in data innovation, the ...

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...