I am trying to create a props.conf to pass a custom timestamp. To do so I wanted to upload data and use thesetsourcetypepage to configure timestamp parameters and then copy the props.conf to c...
...onfirm thesettings. Here is a copy of the btool output:
[default]
countPerPage =
dispatch.earliest_time = @d
dispatch.latest_time = now
display.events.fields = ["host","source","sourcetype"]
d...
...se my browser to connect to an indexer UI page, use the UI's Add Data feature, upload the log file directly and specifically picked altr_web as its sourcetype. Again, when I search (on my search h...
...oken to re-evaluate every time one of the associated inputs is changed?
Setting "Search on Change" to true for relevant inputs has no effect.
I have trimmed my dashboard Source code as f...
Hi, i'm using the splunk cloud platform for a school project. When I import my csv files into splunk, it doesn't seem to recognise the headers of my csv as a field. Does anyone know how to g...
Hello, I have a text source file with header. Some sample events (first line is a header) and props that I wrote given below. My props is working ok, except it breaks the events at TEST\2qw123|E...
...tings' as follows:
NO_BINARY_CHECK=1
TRUNCATE=1048576
CHECK_FOR_HEADER=true
KV_MODE=none
SHOULD_LINEMERGE=false
pulldown-type=true
I then saved this as a new sourcetype...
From the HTTP Event Collector setting page:
SourcetypeThesourcetype is one of the default fields that Splunk assigns to all incoming data. It tells Splunk what kind of data you've got, so t...