Getting Data In

Does anyone know which props.conf keys work with wildcarded stanzas and which dont?

sideview
SplunkTrust
SplunkTrust

I'm having to use wildcarded stanzas for a lot of my sourcetypes in props.conf, and although I'd like to have the core config appear just once in the file, I'm finding that some keys actually do not function in wildcarded stanzas - these keys only work when present in a plain old [actualSourcetypeName] stanza.

So far I've found that CHECK_FOR_HEADER, SHOULD_LINEMERGE and pulldown_type really have to be in a plain old stanza and do not work in wildcarded props stanzas.

On the other extreme, all EVAL-*, LOOKUP-* and REPORT-* seem to work fine in the wildcarded stanzas.

I'm still testing my way through this and I have yet to test TIME_FORMAT, TIME_PREFIX, BREAK_ONLY_BEFORE_DATE MAX_TIMESTAMP_LOOKAHEAD and initCrcLength. It's feeling like these too will also not work in the wildcarded stanzas.

But does anyone know of a reference in the docs that comes out and says which attributes work this way and which don't?

Tags (1)

alacercogitatus
SplunkTrust
SplunkTrust

I'd agree with sowings, it seems as if Index time extractions are not wildcard-able. You can add TZ to the list that won't wildcard. I was trying to force some IIS TZ and it didn't work on iis-3, but it did on iis.

I don't know if this is mentioned in the Docs anywhere, I haven't seen it.

0 Karma

sowings
Splunk Employee
Splunk Employee

After a preliminary glance at the keys you name, it sounds like it might be the distinction between parse time and search time.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...