my inputfile looks like
i have configured props.conf file and transforms.conf in location C:\Program Files\Splunk\etc\system\local which is as below:
**props.conf** [text] NO_BINARY_CHECK = 1 KV_MODE=none SHOULD_LINEMERGE=false REPORT-comment=Extract_text **transforms.conf** [Extract_text] DELIMS= "|" FIELDS= "empid","name","age"
but after restarting splunk i am not getting the fields empid,name and age getting extracted in splunk web interface on left panel
can any one help on this becuase my requirement is to make log data in table format using table query in
I believe that your inputs.conf needs to reference a sourcetype. The sourcetype is the classification of your data.
In props.conf you have a stanza with [text] therefore the sourcetype set for your input should have:
[default] host = 01HW447731 sourcetype=text
* This stanza enables properties for a given
* A props.conf file can contain multiple stanzas for any number of different
* Follow this stanza name with any number of the following attribute/value pairs, as appropriate
for what you want to do.
* If you do not set an attribute for a given