Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- /opt/splunk/etc/slave-apps/_cluster/local/props.conf [host::vsp.my-domain.de]
- /opt/splunk/etc/system/default/props.conf ANNOTATE_PUNCT = True
- /opt/splunk/etc/system/default/props.conf AUTO_KV_JSON = true
- /opt/splunk/etc/system/default/props.conf BREAK_ONLY_BEFORE =
- /opt/splunk/etc/system/default/props.conf BREAK_ONLY_BEFORE_DATE = True
- /opt/splunk/etc/system/default/props.conf CHARSET = UTF-8
- /opt/splunk/etc/system/default/props.conf DATETIME_CONFIG = /etc/datetime.xml
- /opt/splunk/etc/system/default/props.conf HEADER_MODE =
- /opt/splunk/etc/system/default/props.conf LEARN_MODEL = true
- /opt/splunk/etc/system/default/props.conf LEARN_SOURCETYPE = true
- /opt/splunk/etc/system/default/props.conf LINE_BREAKER_LOOKBEHIND = 100
- /opt/splunk/etc/system/default/props.conf MATCH_LIMIT = 100000
- /opt/splunk/etc/system/default/props.conf MAX_DAYS_AGO = 2000
- /opt/splunk/etc/system/default/props.conf MAX_DAYS_HENCE = 2
- /opt/splunk/etc/system/default/props.conf MAX_DIFF_SECS_AGO = 3600
- /opt/splunk/etc/system/default/props.conf MAX_DIFF_SECS_HENCE = 604800
- /opt/splunk/etc/system/default/props.conf MAX_EVENTS = 256
- /opt/splunk/etc/system/default/props.conf MAX_TIMESTAMP_LOOKAHEAD = 128
- /opt/splunk/etc/system/default/props.conf MUST_BREAK_AFTER =
- /opt/splunk/etc/system/default/props.conf MUST_NOT_BREAK_AFTER =
- /opt/splunk/etc/system/default/props.conf MUST_NOT_BREAK_BEFORE =
- /opt/splunk/etc/system/default/props.conf SEGMENTATION = indexing
- /opt/splunk/etc/system/default/props.conf SEGMENTATION-all = full
- /opt/splunk/etc/system/default/props.conf SEGMENTATION-inner = inner
- /opt/splunk/etc/system/default/props.conf SEGMENTATION-outer = outer
- /opt/splunk/etc/system/default/props.conf SEGMENTATION-raw = none
- /opt/splunk/etc/system/default/props.conf SEGMENTATION-standard = standard
- /opt/splunk/etc/system/default/props.conf SHOULD_LINEMERGE = True
- /opt/splunk/etc/system/default/props.conf TRANSFORMS =
- /opt/splunk/etc/slave-apps/_cluster/local/props.conf TRANSFORMS-host_rename = host_rename-vsp.my-domain.de
- /opt/splunk/etc/system/default/props.conf TRUNCATE = 10000
- /opt/splunk/etc/system/default/props.conf detect_trailing_nulls = false
- /opt/splunk/etc/system/default/props.conf maxDist = 100
- /opt/splunk/etc/system/default/props.conf priority =
- /opt/splunk/etc/system/default/props.conf sourcetype =
- /opt/splunk/etc/slave-apps/_cluster/local/transforms.conf [host_rename-vsp.my-domain.de]
- /opt/splunk/etc/system/default/transforms.conf CAN_OPTIMIZE = True
- /opt/splunk/etc/system/default/transforms.conf CLEAN_KEYS = True
- /opt/splunk/etc/system/default/transforms.conf DEFAULT_VALUE =
- /opt/splunk/etc/slave-apps/_cluster/local/transforms.conf DEST_KEY = MetaData:Host
- /opt/splunk/etc/slave-apps/_cluster/local/transforms.conf FORMAT = host::somehost.local.lan
- /opt/splunk/etc/system/default/transforms.conf KEEP_EMPTY_VALS = False
- /opt/splunk/etc/system/default/transforms.conf LOOKAHEAD = 4096
- /opt/splunk/etc/system/default/transforms.conf MATCH_LIMIT = 100000
- /opt/splunk/etc/system/default/transforms.conf MV_ADD = False
- /opt/splunk/etc/slave-apps/_cluster/local/transforms.conf REGEX = .*
- /opt/splunk/etc/system/default/transforms.conf SOURCE_KEY = _raw
- /opt/splunk/etc/system/default/transforms.conf WRITE_META = False
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement