Advertisement
Guest User

props/transforms

a guest
Apr 15th, 2017
79
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 4.27 KB | None | 0 0
  1. /opt/splunk/etc/slave-apps/_cluster/local/props.conf [host::vsp.my-domain.de]
  2. /opt/splunk/etc/system/default/props.conf ANNOTATE_PUNCT = True
  3. /opt/splunk/etc/system/default/props.conf AUTO_KV_JSON = true
  4. /opt/splunk/etc/system/default/props.conf BREAK_ONLY_BEFORE =
  5. /opt/splunk/etc/system/default/props.conf BREAK_ONLY_BEFORE_DATE = True
  6. /opt/splunk/etc/system/default/props.conf CHARSET = UTF-8
  7. /opt/splunk/etc/system/default/props.conf DATETIME_CONFIG = /etc/datetime.xml
  8. /opt/splunk/etc/system/default/props.conf HEADER_MODE =
  9. /opt/splunk/etc/system/default/props.conf LEARN_MODEL = true
  10. /opt/splunk/etc/system/default/props.conf LEARN_SOURCETYPE = true
  11. /opt/splunk/etc/system/default/props.conf LINE_BREAKER_LOOKBEHIND = 100
  12. /opt/splunk/etc/system/default/props.conf MATCH_LIMIT = 100000
  13. /opt/splunk/etc/system/default/props.conf MAX_DAYS_AGO = 2000
  14. /opt/splunk/etc/system/default/props.conf MAX_DAYS_HENCE = 2
  15. /opt/splunk/etc/system/default/props.conf MAX_DIFF_SECS_AGO = 3600
  16. /opt/splunk/etc/system/default/props.conf MAX_DIFF_SECS_HENCE = 604800
  17. /opt/splunk/etc/system/default/props.conf MAX_EVENTS = 256
  18. /opt/splunk/etc/system/default/props.conf MAX_TIMESTAMP_LOOKAHEAD = 128
  19. /opt/splunk/etc/system/default/props.conf MUST_BREAK_AFTER =
  20. /opt/splunk/etc/system/default/props.conf MUST_NOT_BREAK_AFTER =
  21. /opt/splunk/etc/system/default/props.conf MUST_NOT_BREAK_BEFORE =
  22. /opt/splunk/etc/system/default/props.conf SEGMENTATION = indexing
  23. /opt/splunk/etc/system/default/props.conf SEGMENTATION-all = full
  24. /opt/splunk/etc/system/default/props.conf SEGMENTATION-inner = inner
  25. /opt/splunk/etc/system/default/props.conf SEGMENTATION-outer = outer
  26. /opt/splunk/etc/system/default/props.conf SEGMENTATION-raw = none
  27. /opt/splunk/etc/system/default/props.conf SEGMENTATION-standard = standard
  28. /opt/splunk/etc/system/default/props.conf SHOULD_LINEMERGE = True
  29. /opt/splunk/etc/system/default/props.conf TRANSFORMS =
  30. /opt/splunk/etc/slave-apps/_cluster/local/props.conf TRANSFORMS-host_rename = host_rename-vsp.my-domain.de
  31. /opt/splunk/etc/system/default/props.conf TRUNCATE = 10000
  32. /opt/splunk/etc/system/default/props.conf detect_trailing_nulls = false
  33. /opt/splunk/etc/system/default/props.conf maxDist = 100
  34. /opt/splunk/etc/system/default/props.conf priority =
  35. /opt/splunk/etc/system/default/props.conf sourcetype =
  36.  
  37.  
  38.  
  39. /opt/splunk/etc/slave-apps/_cluster/local/transforms.conf [host_rename-vsp.my-domain.de]
  40. /opt/splunk/etc/system/default/transforms.conf CAN_OPTIMIZE = True
  41. /opt/splunk/etc/system/default/transforms.conf CLEAN_KEYS = True
  42. /opt/splunk/etc/system/default/transforms.conf DEFAULT_VALUE =
  43. /opt/splunk/etc/slave-apps/_cluster/local/transforms.conf DEST_KEY = MetaData:Host
  44. /opt/splunk/etc/slave-apps/_cluster/local/transforms.conf FORMAT = host::somehost.local.lan
  45. /opt/splunk/etc/system/default/transforms.conf KEEP_EMPTY_VALS = False
  46. /opt/splunk/etc/system/default/transforms.conf LOOKAHEAD = 4096
  47. /opt/splunk/etc/system/default/transforms.conf MATCH_LIMIT = 100000
  48. /opt/splunk/etc/system/default/transforms.conf MV_ADD = False
  49. /opt/splunk/etc/slave-apps/_cluster/local/transforms.conf REGEX = .*
  50. /opt/splunk/etc/system/default/transforms.conf SOURCE_KEY = _raw
  51. /opt/splunk/etc/system/default/transforms.conf WRITE_META = False
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement