Hi,
I'm using Splunk universal Forwarder for sending UiPath Robot logs to Splunk Server. I noticed that some of our logs are being truncate at the end. I searched it on the internet and my understanding is that I have to change Truncate value in props.conf for Universal Forwarder. I could not figure out where should be the props.conf file changed In the beginning I changed
C:\ProgramFiles\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\default\props.conf but then I got to know that you're not supposed to make changings in default configs, So I removed the line from there. Then I added a props.config file by myself at the location C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local\props.conf because there wasn't any, So I thought maybe we have to add it on our own. I used the following lines in props.conf
[default] Truncate = 50000
Still I could not see any changings in Splunk logs. Then I read somewhere that you need to restart your forwarder for changes to take place. I used the following command
C:\Program Files\SplunkUniversalForwarder\bin>splunk.exe restart
and got the following error
Invalid key in stanza [default] in C:\Program Files\SplunkUniversalForwarder\etc\apps\SplunkUniversalForwarder\local\props.conf, line 2: Truncate (value: 50). Your indexes and inputs configurations are not internally consistent. For more information, run 'splunk btool check --debug' Done Checking default conf files for edits... Validating installed files against hashes from'C:\Program Files\SplunkUniversalForwarder\splunkforwarder-8.0.5-a1a6394cc5ae-windows-64-manifest' File 'C:\Program Files\SplunkUniversalForwarder\etc/apps/SplunkUniversalForwarder/default/props.conf' changed. Problems were found, please review your files and move customizations to local All preliminary checks passed. Starting splunk server daemon (splunkd)... SplunkForwarder: Unable to start the service: Access is denied.
I am very new to splunk so I don't have any idea of these things. I assume that may be I'm doing it wrong. Can someone please answer my following questions
Where do I need to add props.conf?
What should I add in props.conf and what should be the syntax?
After doing the above how to restart splunk?
Any help will be much appreciated. Thanks 🙂
... View more