Splunk Search

PROF Conf Issues

SplunkDash
Motivator

Hello, I was trying to write PROPS configuration file following sample events...

2021-06-08T13:26:53.665000-04:00|PGM|mtb1120ppcdwap6|vggtb|26462|

2021-06-08T13:26:54.478000-04:00|PGM|mtb1120ppcdwap6|vggtb|26462|

 

since it has pipe "|"..here is what I wrote..but not working... Any help will be highly appreciated...thank you so much..

SHOULD_LINEMERGE = false

LINE_BREAKER = ([\r\n]+)

INDEXED_EXTRACTIONS = psv

TIME_FORMAT = %Y%m%d %H:%M:%S:%Q

TIMESTAMP_FIELDS = TIMESTAMP

 

Labels (1)
Tags (1)
0 Karma

anilchaithu
Builder

@SplunkDash 

How are you onboarding this data?

If you are onboarding this data from a remote server using UF, you should place the props.conf on the remote server to extract the fields.

Its always better to test the extraction using UI i.e. settings -> Add Data -> upload -> choose psv as sourcetype. Once you are ok with extraction, copy the parameters deploy it over to the UF.

If this psv file does not has a header file, you need to mention the fields as well in the props.conf.

 

-- Hope this helps.

Get Updates on the Splunk Community!

New Year. New Skills. New Course Releases from Splunk Education

A new year often inspires reflection—and reinvention. Whether your goals include strengthening your security ...

Splunk and TLS: It doesn't have to be too hard

Overview Creating a TLS cert for Splunk usage is pretty much standard openssl.  To make life better, use an ...

Faster Insights with AI, Streamlined Cloud-Native Operations, and More New Lantern ...

Splunk Lantern is a Splunk customer success center that provides practical guidance from Splunk experts on key ...