Hello Everyone,
Now a days when I extract fields, need 1000ea fields.
so, i defined in transforms.conf and props.conf about 1000 ea fields.
But Splunk can not recognizes.
I configured.
props.conf
[sourcetype]
REPORT-sourcetype = delimExtractions_CC_type
transforms.conf
[delimExtractions_CC_type]
DELIMS = "|"
FIELDS = "time", "A0001","A0002","A0003","A0004",.... "A1713","A1714","A1715"
I need add something in transforms.conf and props.conf?
... View more