Hello guys,
I am new to splunk and I am having troubles in getting my changes to props.conf (from .../Splunk/etc/apps/search/local ) to take effect in Splunk. I changed the values to my source type, but they stay like they were before.
I originally created that source type as a step while "adding data" in Splunk, via the "Set Source Type" fields, then I saved the created source type via "save as" under a name in category "Custom".
Then I found my created source type in the props.conf in .../Splunk/etc/apps/search/local and tried to manually edit it via text editor. After that, I restarted Splunk and wanted to add new data using my new (manually edited) source type, but unfortunately, the changes I manually edited did not take effect.
Any ideas please? Thank you in advance guys!
Please note:
- I am using Splunk Light
- I did restart Splunk (log out from Splunk Web session and then restart and login)
... View more