Upon an upgrade to 4.2 I noticed that splunk spit out the following:
Possible typo in stanza [source::/tmp/test.csv] in /opt/splunk/etc/system/local/props.conf, line 16: CLEAN_KEYS = false
Did you mean 'CHARSET'?
Did you mean 'CHECK_FOR_HEADER'?
Did you mean 'CHECK_METHOD'?
Did you mean 'Conversely, if you commonly search a large event set with expressions like company_id!'?
Did CLEAN_KEYS get phased out of Splunk 4.2? I don't see any mention of it anywhere...
Thanks, Josh
CLEAN_KEYS is actually a transforms.conf setting, not props.conf. This is why config checker is barking. It's not actually a typo, but an invalid setting for props.conf. http://www.splunk.com/base/Documentation/latest/Admin/Transformsconf
CLEAN_KEYS is actually a transforms.conf setting, not props.conf. This is why config checker is barking. It's not actually a typo, but an invalid setting for props.conf. http://www.splunk.com/base/Documentation/latest/Admin/Transformsconf
Ah shoot, you are right, that's my bad. Thanks for pointing out my oversight!