Hi,
I have been using a props.conf file to extract fields in my event logs, but it does not seem to be working. Below are the sample props.conf and event. Any help is much appreciated.
C:\Program Files\SplunkUniversalForwarder\etc\apps\my_app\local\props.conf
[Script:WinService]
EXTRACT-service = SERVICE_NAME: (?<service_name>\S*)
EXTRACT-state = STATE\s*?: [0-9]\s*(?<state>\S*)
and the event is shown in attached image.
Many thanks in advance.
Regards,
Rajnish Kumar
You need to place the props.conf
containing field extractions on your search head. A Universal Forwarder will ignore EXTRACT
configurations in props.conf.
You need to place the props.conf
containing field extractions on your search head. A Universal Forwarder will ignore EXTRACT
configurations in props.conf.
Thanks Mason for your response. My app resides on my forwarder as shown in my question. In this case which directory I should put my props.conf file in on my search head?