Splunk Search

Trying to bring in an NFS share of JSON files, why are they coming up as individual line items when I search with no field extractions?

Builder

All,

Trying to bring in a NFS share of JSON files, but they are coming up as individual line items when I search with no extractions. Did I miss something?

TA-company-akamai-networklists - inputs.conf

[monitor:///NFS/utl/akamai/networklists/*]
index=main
sourcetype=akamai:networklists

SA-COMPANY-akamai-props.conf - props.conf

[akamai:networklists]
 DATETIME_CONFIG = CURRENT
 KV_MODE = json
 NO_BINARY_CHECK = 1
 TRUNCATE = 0
 SHOULD_LINEMERGE = true
 MAX_EVENTS = 20000
0 Karma

Influencer

This happened to me the other day - you're not running in fast mode by any chance are you?

0 Karma

SplunkTrust
SplunkTrust

Dumb question, did you put the props.conf on Indexers and restarted Indexer?

0 Karma