<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Index time props and transforms not working in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Index-time-props-and-transforms-not-working/m-p/113633#M23784</link>
    <description>&lt;P&gt;If it works in Dev then the only thing that could be wrong is that you have not put the files in the right place on your Indexers or that you have not restarted the Splunk instances on your Indexers.  You did restart Splunk on your Indexers, right?&lt;/P&gt;</description>
    <pubDate>Thu, 06 Aug 2015 02:39:40 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2015-08-06T02:39:40Z</dc:date>
    <item>
      <title>Index time props and transforms not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-time-props-and-transforms-not-working/m-p/113630#M23781</link>
      <description>&lt;P&gt;I have the following props &amp;amp; transforms in splunk dev and prod environment monitoring the same set of iis logs:&lt;/P&gt;

&lt;H1&gt;props.conf&lt;/H1&gt;

&lt;PRE&gt;&lt;CODE&gt;[source::/var/www/logs/someiislog2*]
CHECK_FOR_HEADER=false
TZ = UTC
pulldown_type = true
MAX_TIMESTAMP_LOOKAHEAD = 32
SHOULD_LINEMERGE = false
EXTRACT-SiteID = (?W3SVC\d+) in source
REPORT-iisFields= iis-c
SEDCMD-001TrimWhiteSpace = s/(\s)\s+/\1/g
SEDCMD-002RemoveCookie = s/(.*\s\d{1,}\.\d{1,}\.\d{1,}\.\d{1,})\s\S+\s(\S+\s.*)/\1 - \2/g
TRANSFORMS-ToIisSourceType = forcetoIISsourcetype
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;H1&gt;transforms.conf&lt;/H1&gt;

&lt;PRE&gt;&lt;CODE&gt;[iis-c]
DELIMS = " "
FIELDS = date, time, cs_method, cs_uri_stem, cs_uri_query, c_ip, cs_Cookie, cs_Referer, cs_host, sc_status, sc_bytes, time_taken

[forcetoIISsourcetype]
REGEX = .
DEST_KEY = MetaData:Sourcetype
FORMAT = sourcetype::iis
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Everything works in dev, but in prod, none of the index-time stuff (SEDCMD and TRANSFORMS-ToIisSourceType ) appears to be working.  I have checked the splunkd.log but did not find any relevant message.&lt;/P&gt;

&lt;P&gt;How can I further troubleshoot this issue?  Which debug parameters can I enable to gather more information?&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jan 2014 21:50:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-time-props-and-transforms-not-working/m-p/113630#M23781</guid>
      <dc:creator>splunkIT</dc:creator>
      <dc:date>2014-01-14T21:50:30Z</dc:date>
    </item>
    <item>
      <title>Re: Index time props and transforms not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-time-props-and-transforms-not-working/m-p/113631#M23782</link>
      <description>&lt;P&gt;Obvious, but are they placed in indexers?&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jan 2014 18:38:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-time-props-and-transforms-not-working/m-p/113631#M23782</guid>
      <dc:creator>linu1988</dc:creator>
      <dc:date>2014-01-22T18:38:00Z</dc:date>
    </item>
    <item>
      <title>Re: Index time props and transforms not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-time-props-and-transforms-not-working/m-p/113632#M23783</link>
      <description>&lt;P&gt;Is there a UF in here and which Splunk clients have your props settings?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Aug 2015 22:28:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-time-props-and-transforms-not-working/m-p/113632#M23783</guid>
      <dc:creator>landen99</dc:creator>
      <dc:date>2015-08-05T22:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: Index time props and transforms not working</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-time-props-and-transforms-not-working/m-p/113633#M23784</link>
      <description>&lt;P&gt;If it works in Dev then the only thing that could be wrong is that you have not put the files in the right place on your Indexers or that you have not restarted the Splunk instances on your Indexers.  You did restart Splunk on your Indexers, right?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Aug 2015 02:39:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-time-props-and-transforms-not-working/m-p/113633#M23784</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-08-06T02:39:40Z</dc:date>
    </item>
  </channel>
</rss>

