Splunk Search

Negative lookahead for props.conf

htidore
Path Finder

I am trying to create a stanza in props.conf so that all non splunk internal logs go to index=newindex.

I tried using negative lookahead as follow:

[source::^(?!.*log\/*\\*splunk).*$]

But it doesn't work.
Thanks.

Tags (2)
0 Karma

manjunathmeti
Champion

Instead of using props.conf you can use inputs.conf to route internal logs to other index.

[monitor://$SPLUNK_HOME/var/log/splunk]
index = newindex
0 Karma

htidore
Path Finder

We cannot change the config at UF.

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...