<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Props and Transforms doubt in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Props-and-Transforms-doubt/m-p/704547#M116525</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/187813"&gt;@sainag_splunk&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Also please explain what is index peers you mean and index cluster bundle?&lt;/P&gt;&lt;P&gt;Please reply&lt;/P&gt;</description>
    <pubDate>Sat, 16 Nov 2024 06:24:11 GMT</pubDate>
    <dc:creator>Karthikeya</dc:creator>
    <dc:date>2024-11-16T06:24:11Z</dc:date>
    <item>
      <title>Props and Transforms doubt</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-and-Transforms-doubt/m-p/704157#M116462</link>
      <description>&lt;P&gt;I am new to Splunk admin and please explain this following stanzas:&lt;/P&gt;&lt;P&gt;We have a dedicated syslog server which receives the logs from network devices and UF installed on the server forwards the data to our cluster manager. These configs are in cluster manager under manager apps.&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2024 11:21:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-and-Transforms-doubt/m-p/704157#M116462</guid>
      <dc:creator>Karthikeya</dc:creator>
      <dc:date>2024-11-16T11:21:13Z</dc:date>
    </item>
    <item>
      <title>Re: Props and Transforms doubt</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-and-Transforms-doubt/m-p/704228#M116470</link>
      <description>&lt;OL class=""&gt;&lt;LI&gt;Data Flow:&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Data goes DIRECTLY from UF to indexers on port 9997 (not to cluster manager)&lt;/P&gt;&lt;P&gt;Cluster Manager only handles configuration distribution&lt;/P&gt;&lt;OL class=""&gt;&lt;LI&gt;Configuration Management:&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Props and transforms configs are deployed via cluster manager&lt;/P&gt;&lt;P&gt;These configs are pushed to index peers via index cluster bundle&lt;/P&gt;&lt;OL class=""&gt;&lt;LI&gt;Processing Location:&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;All parsing happens on the indexers (index peers)&lt;/P&gt;&lt;P&gt;Each indexer applies the deployed configurations independently&lt;/P&gt;&lt;P class=""&gt;For Deep Understanding: Refer:&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Diagrams-of-how-indexing-works-in-the-Splunk-platform-the-Masa/m-p/590774" target="_blank" rel="noopener"&gt;https://community.splunk.com/t5/Getting-Data-In/Diagrams-of-how-indexing-works-in-the-Splunk-platform-the-Masa/m-p/590774&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;UL class=""&gt;&lt;LI&gt;Review props.conf documentation: docs.splunk.com/Documentation/Splunk/9.1.0/Admin/Propsconf&lt;/LI&gt;&lt;LI&gt;&amp;nbsp;docs.splunk.com/Documentation/ITSI/4.17.0/Configure/transforms.conf&lt;/LI&gt;&lt;/UL&gt;&lt;P class=""&gt;Since there are many pipeline components, I encourage you to read through these resources for a complete understanding.&lt;BR /&gt;&lt;BR /&gt;Simple Data Flow here.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-11-12 at 5.55.15 PM.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33453iB32D81F1073D9612/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2024-11-12 at 5.55.15 PM.png" alt="Screenshot 2024-11-12 at 5.55.15 PM.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;If this Helps, Please Upvote.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Nov 2024 23:57:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-and-Transforms-doubt/m-p/704228#M116470</guid>
      <dc:creator>sainag_splunk</dc:creator>
      <dc:date>2024-11-12T23:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: Props and Transforms doubt</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-and-Transforms-doubt/m-p/704248#M116473</link>
      <description>&lt;P&gt;Thank you &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/187813"&gt;@sainag_splunk&lt;/a&gt;&amp;nbsp;..&lt;/P&gt;&lt;P&gt;Then what about inputs.conf and outputs.conf (i believe it will not be there considering it's indexer) in indexer cluster should be configured?&lt;/P&gt;&lt;P&gt;We have deployment server as well. Can you please let me know where it will be there in picture?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Nov 2024 07:26:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-and-Transforms-doubt/m-p/704248#M116473</guid>
      <dc:creator>Karthikeya</dc:creator>
      <dc:date>2024-11-13T07:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: Props and Transforms doubt</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-and-Transforms-doubt/m-p/704547#M116525</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/187813"&gt;@sainag_splunk&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Also please explain what is index peers you mean and index cluster bundle?&lt;/P&gt;&lt;P&gt;Please reply&lt;/P&gt;</description>
      <pubDate>Sat, 16 Nov 2024 06:24:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-and-Transforms-doubt/m-p/704547#M116525</guid>
      <dc:creator>Karthikeya</dc:creator>
      <dc:date>2024-11-16T06:24:11Z</dc:date>
    </item>
    <item>
      <title>Re: Props and Transforms doubt</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Props-and-Transforms-doubt/m-p/704657#M116553</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/273888"&gt;@Karthikeya&lt;/a&gt;&amp;nbsp;Index peers are simply indexers that work together in a Splunk cluster environment. They are responsible for receiving, processing, and storing data while maintaining copies across multiple indexers for redundancy and high availability. When a Cluster Master pushes configuration changes through an index cluster bundle, all index peers receive the same settings to ensure consistent operation across the cluster.&lt;BR /&gt;&lt;BR /&gt;Refer:&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.3.2/Indexer/Basicclusterarchitecture" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.3.2/Indexer/Basicclusterarchitecture&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.3.2/Indexer/Howclusteredindexingworks" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/9.3.2/Indexer/Howclusteredindexingworks&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;If this Helps, Please Upvote and Mark as solved.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-11-18 at 10.30.11 AM.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/33500iD61242CFF7F7B0EA/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot 2024-11-18 at 10.30.11 AM.png" alt="Screenshot 2024-11-18 at 10.30.11 AM.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 18 Nov 2024 16:31:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Props-and-Transforms-doubt/m-p/704657#M116553</guid>
      <dc:creator>sainag_splunk</dc:creator>
      <dc:date>2024-11-18T16:31:32Z</dc:date>
    </item>
  </channel>
</rss>

