Hello,
I use Splunk as Indexer and deployment server und I have one universal forwarder installed.
I'm getting an error, when Splunk forwarder tries to read one log file:
Ignoring file '/mnt/scn_data/log.txt' due to: binary
It works, after I put a file props.conf into app folder on the forwarder.
[cx_scan_logs]
CHARSET = UTF-16LE
LINE_BREAKER = ([\r\n]+)
NO_BINARY_CHECK = true
category = Custom
But after I made changes on the index server, the files on the forwarder like inputs.conf are updated and props.conf is deleted. And I get the error again.
How can I say the Splunk not to delete the props.conf on the forwarder?
Hi @alpeen_splunk,
did you added the props.conf file only to the $SPLUNK_HOME/etc/apps/<your_app> folder or also to the $SPLUNK_HOME/etc/deployment-apps folder?
If a client is managed by a DS, you have to put the apps to deploy in the $SPLUNK_HOME/etc/deployment-apps folder.
Ciao.
Giuseppe
Hi @alpeen_splunk,
did you added the props.conf file only to the $SPLUNK_HOME/etc/apps/<your_app> folder or also to the $SPLUNK_HOME/etc/deployment-apps folder?
If a client is managed by a DS, you have to put the apps to deploy in the $SPLUNK_HOME/etc/deployment-apps folder.
Ciao.
Giuseppe
Hi Giuseppe,
thank you very much for your so quick replay!
I've copied props.conf from .../apps/MyApp/local folder to .../deployment-app/MyApp/local.
Now it works as expected.
Hi @alpeen_splunk,
good for you, see next time!
Ciao and happy splunking
Giuseppe
P.S.: Karma Points are appreciated 😉