Splunk Search

PROF Conf Issues

SplunkDash
Motivator

Hello, I was trying to write PROPS configuration file following sample events...

2021-06-08T13:26:53.665000-04:00|PGM|mtb1120ppcdwap6|vggtb|26462|

2021-06-08T13:26:54.478000-04:00|PGM|mtb1120ppcdwap6|vggtb|26462|

 

since it has pipe "|"..here is what I wrote..but not working... Any help will be highly appreciated...thank you so much..

SHOULD_LINEMERGE = false

LINE_BREAKER = ([\r\n]+)

INDEXED_EXTRACTIONS = psv

TIME_FORMAT = %Y%m%d %H:%M:%S:%Q

TIMESTAMP_FIELDS = TIMESTAMP

 

Labels (1)
Tags (1)
0 Karma

anilchaithu
Builder

@SplunkDash 

How are you onboarding this data?

If you are onboarding this data from a remote server using UF, you should place the props.conf on the remote server to extract the fields.

Its always better to test the extraction using UI i.e. settings -> Add Data -> upload -> choose psv as sourcetype. Once you are ok with extraction, copy the parameters deploy it over to the UF.

If this psv file does not has a header file, you need to mention the fields as well in the props.conf.

 

-- Hope this helps.

Get Updates on the Splunk Community!

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...