Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

props.conf not effective

$
0
0
Hi, this issue has been mentioned here before but still my properties is props.conf are not effective. Here is the configuration I'm using : Inputs.conf : [default] host = bb1322454b5f sourcetype=analyteacs_sales source=splunk:8088 Transforms.conf : [clone_ebook_sales] REGEX = (?s).* CLONE_SOURCETYPE = ebook_sales_for_resellers DEST_KEY = _MetaData:Index FORMAT = ebook_sales A finally props.conf : [analyteacs_sales] TRANSFORMS-clone_ebook_sales = clone_ebook_sales tz = Pacific/Fiji sourcetype=ebook_sales priority=100 I tried to modify the system's timezone, but the changes aren't effective. Does someone see where it comes from? Thanks in advance

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>