<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Index time fields ignored in cluster in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Index-time-fields-ignored-in-cluster/m-p/190840#M38000</link>
    <description>&lt;P&gt;I have a cluster setup with search head, master, 3 indexers and a forwarder. The index config is pushed from the master (and I can see after splunk apply cluster-bundle) that it successfully turns up on each index node.  The problem is that all the index time transforms I have entered are being ignored.&lt;/P&gt;

&lt;P&gt;I have the same symptoms as this question (&lt;A href="http://answers.splunk.com/answers/93776/push-configuration-files-in-cluster"&gt;http://answers.splunk.com/answers/93776/push-configuration-files-in-cluster&lt;/A&gt;) but my fields are extracted at index time.  I successfully applied the same config (or at least I &lt;EM&gt;thought&lt;/EM&gt; it was the same) on a separate cluster and that worked fine.  Can anyone point me in the right direction to debug why the transforms are not being applied?&lt;/P&gt;

&lt;P&gt;Similar also to this issue: &lt;A href="http://answers.splunk.com/answers/118649/index-time-props-and-transforms-not-working"&gt;http://answers.splunk.com/answers/118649/index-time-props-and-transforms-not-working&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Splunk Enterprise 6.1&lt;/P&gt;</description>
    <pubDate>Fri, 06 Jun 2014 08:50:07 GMT</pubDate>
    <dc:creator>charltones</dc:creator>
    <dc:date>2014-06-06T08:50:07Z</dc:date>
    <item>
      <title>Index time fields ignored in cluster</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-time-fields-ignored-in-cluster/m-p/190840#M38000</link>
      <description>&lt;P&gt;I have a cluster setup with search head, master, 3 indexers and a forwarder. The index config is pushed from the master (and I can see after splunk apply cluster-bundle) that it successfully turns up on each index node.  The problem is that all the index time transforms I have entered are being ignored.&lt;/P&gt;

&lt;P&gt;I have the same symptoms as this question (&lt;A href="http://answers.splunk.com/answers/93776/push-configuration-files-in-cluster"&gt;http://answers.splunk.com/answers/93776/push-configuration-files-in-cluster&lt;/A&gt;) but my fields are extracted at index time.  I successfully applied the same config (or at least I &lt;EM&gt;thought&lt;/EM&gt; it was the same) on a separate cluster and that worked fine.  Can anyone point me in the right direction to debug why the transforms are not being applied?&lt;/P&gt;

&lt;P&gt;Similar also to this issue: &lt;A href="http://answers.splunk.com/answers/118649/index-time-props-and-transforms-not-working"&gt;http://answers.splunk.com/answers/118649/index-time-props-and-transforms-not-working&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Splunk Enterprise 6.1&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jun 2014 08:50:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-time-fields-ignored-in-cluster/m-p/190840#M38000</guid>
      <dc:creator>charltones</dc:creator>
      <dc:date>2014-06-06T08:50:07Z</dc:date>
    </item>
    <item>
      <title>Re: Index time fields ignored in cluster</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Index-time-fields-ignored-in-cluster/m-p/190841#M38001</link>
      <description>&lt;P&gt;I think the answer is that either:&lt;/P&gt;

&lt;OL&gt;
&lt;LI&gt;This doesn't work - you can't have index time fields carried out by indexers in a cluster
or &lt;/LI&gt;
&lt;LI&gt;It is because I was using a heavy forwarder - i.e. it believed the indexing work had already been done.&lt;/LI&gt;
&lt;/OL&gt;

&lt;P&gt;I didn't realise I was using a heavy forwarder, but I've fixed my problem by moving the indexing config to the forwarder instead and it is all behaving as expected now&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jun 2014 16:56:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Index-time-fields-ignored-in-cluster/m-p/190841#M38001</guid>
      <dc:creator>charltones</dc:creator>
      <dc:date>2014-06-10T16:56:17Z</dc:date>
    </item>
  </channel>
</rss>

