Getting Data In

Does anyone know which props.conf keys work with wildcarded stanzas and which dont?

sideview
SplunkTrust
SplunkTrust

I'm having to use wildcarded stanzas for a lot of my sourcetypes in props.conf, and although I'd like to have the core config appear just once in the file, I'm finding that some keys actually do not function in wildcarded stanzas - these keys only work when present in a plain old [actualSourcetypeName] stanza.

So far I've found that CHECK_FOR_HEADER, SHOULD_LINEMERGE and pulldown_type really have to be in a plain old stanza and do not work in wildcarded props stanzas.

On the other extreme, all EVAL-*, LOOKUP-* and REPORT-* seem to work fine in the wildcarded stanzas.

I'm still testing my way through this and I have yet to test TIME_FORMAT, TIME_PREFIX, BREAK_ONLY_BEFORE_DATE MAX_TIMESTAMP_LOOKAHEAD and initCrcLength. It's feeling like these too will also not work in the wildcarded stanzas.

But does anyone know of a reference in the docs that comes out and says which attributes work this way and which don't?

Tags (1)

alacercogitatus
SplunkTrust
SplunkTrust

I'd agree with sowings, it seems as if Index time extractions are not wildcard-able. You can add TZ to the list that won't wildcard. I was trying to force some IIS TZ and it didn't work on iis-3, but it did on iis.

I don't know if this is mentioned in the Docs anywhere, I haven't seen it.

0 Karma

sowings
Splunk Employee
Splunk Employee

After a preliminary glance at the keys you name, it sounds like it might be the distinction between parse time and search time.

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...