Quantcast
Channel: Questions in topic: "props.conf"
Viewing all articles
Browse latest Browse all 1485

After deploying KV_MODE = auto_escaped in props.conf to my search head cluster, why are we seeing unexpected search results?

$
0
0
I am trying to set up KV_MODE = auto_escaped for a particular source. The stanza looks like the following: [source:///var/log/test.log] KV_MODE = auto_escaped I used the test data directly from the Splunk documentation: field = "value with \"nested\" quotes." The resulting search shows the field, field with a value with `\`. I have set this in the props.conf on the deployer in the following areas: $SPLUNKHOME/etc/master-apps/_cluster/local/props.conf $SPLUNKHOME/etc/shcluster/apps/search/props.conf Neither of these produce the correct results.

Viewing all articles
Browse latest Browse all 1485

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>