Getting Data In

props. conf file help

chimbudp
Contributor

Using [monitor://path] Stanza i need to monitor a folder which contains binary data.
When i set the props.conf as,

[assembly]
NO_BINARY_CHECK = true

It simply forwards the binary data into splunk , and of no use.
I need to configure props.conf from universal forwarder to identify the binary data and send useful data to splunk.

please help me.

Tags (1)
0 Karma

Ayn
Legend

Ok this is getting annoying. You've been told multiple times that your approach won't work.

Now, in your question you state that you're STILL using monitor (even though you've been told this won't work like you want it to), but in your comment you say you're using fschange. So, which one are you really using?

Also fschange has NOT been removed, it is just deprecated which means the functionality will not be developed further.

It seems to me you've skipped the step of learning the basics of what Splunk is and how it works. Please take the time to getting to know Splunk a bit, it will save you loads of time when you understand the proper way to solve different things, and it will also save the splunkbase community from frustration when repeatedly having to tell you the same thing.

chimbudp
Contributor

Please help me in configuring the inputs.conf & props.conf correctly in forwarder & indexer , stepwise.

0 Karma

chimbudp
Contributor

I am using fschange stanza , since it updates only updates happened in that folder . Also , this feature has been removed in latest Splunk version. 😞

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...