<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: data pipeline and configuration files location in Knowledge Management</title>
    <link>https://community.splunk.com/t5/Knowledge-Management/data-pipeline-and-configuration-files-location/m-p/416160#M6123</link>
    <description>&lt;P&gt;thank you for the answer , but i think i can override sourcetype,index,source and host in inputs.conf in Universal Forwarder , also i can do the same in indexer and Heavy Forwarder.&lt;BR /&gt;
but i think there is the difference between them , in Universal Forwarder i can just write the index where the data will be stored in indexer but i don't have any power to filter the data as in inputs level splunk can't determine the events. in the opposite in indexer , the splunk can parse the data so i can dynamically override (writing regex to change a subset of data or routing some data to index and other to another index) the sourcetype,index,host,source for the data .&lt;BR /&gt;
can you correct me if i'm wrong ??&lt;/P&gt;</description>
    <pubDate>Sat, 08 Jun 2019 22:19:58 GMT</pubDate>
    <dc:creator>ahmedragy922</dc:creator>
    <dc:date>2019-06-08T22:19:58Z</dc:date>
    <item>
      <title>data pipeline and configuration files location</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/data-pipeline-and-configuration-files-location/m-p/416158#M6121</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;
i'm confused about where configuration files (Search Head or Indexer) should i modify when i want to do filed extraction ??&lt;BR /&gt;
or when i want to override sourcetype,source,host , should i do that in forwarder or indexer or search head???&lt;BR /&gt;
is there any reference that map the configuration files to which data pipeline  applies ?? for example : if i want to do field extraction &amp;gt;&amp;gt;&amp;gt; i should do that in Search head and configure props.conf and transforms.conf &lt;/P&gt;

&lt;P&gt;i just found those 2 articles but i still confused.&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.6/Admin/Configurationparametersandthedatapipeline"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.6/Admin/Configurationparametersandthedatapipeline&lt;/A&gt;&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.6/Deploy/Datapipeline"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.6/Deploy/Datapipeline&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jun 2019 16:36:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/data-pipeline-and-configuration-files-location/m-p/416158#M6121</guid>
      <dc:creator>ahmedragy922</dc:creator>
      <dc:date>2019-06-08T16:36:14Z</dc:date>
    </item>
    <item>
      <title>Re: data pipeline and configuration files location</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/data-pipeline-and-configuration-files-location/m-p/416159#M6122</link>
      <description>&lt;P&gt;You might find this page useful: &lt;A href="https://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F"&gt;https://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings%3F&lt;/A&gt;&lt;BR /&gt;
Index-time field extraction (fields that will be stored in the indexes) go in heavy forwarders or indexers, whichever touches the data first.&lt;BR /&gt;
Search-time field extractions (those done during a search) go in search heads.&lt;BR /&gt;
Overrides of sourcetype, source, or host go in heavy forwarders or indexers, whichever touches the data first.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jun 2019 21:36:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/data-pipeline-and-configuration-files-location/m-p/416159#M6122</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-06-08T21:36:55Z</dc:date>
    </item>
    <item>
      <title>Re: data pipeline and configuration files location</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/data-pipeline-and-configuration-files-location/m-p/416160#M6123</link>
      <description>&lt;P&gt;thank you for the answer , but i think i can override sourcetype,index,source and host in inputs.conf in Universal Forwarder , also i can do the same in indexer and Heavy Forwarder.&lt;BR /&gt;
but i think there is the difference between them , in Universal Forwarder i can just write the index where the data will be stored in indexer but i don't have any power to filter the data as in inputs level splunk can't determine the events. in the opposite in indexer , the splunk can parse the data so i can dynamically override (writing regex to change a subset of data or routing some data to index and other to another index) the sourcetype,index,host,source for the data .&lt;BR /&gt;
can you correct me if i'm wrong ??&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jun 2019 22:19:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/data-pipeline-and-configuration-files-location/m-p/416160#M6123</guid>
      <dc:creator>ahmedragy922</dc:creator>
      <dc:date>2019-06-08T22:19:58Z</dc:date>
    </item>
    <item>
      <title>Re: data pipeline and configuration files location</title>
      <link>https://community.splunk.com/t5/Knowledge-Management/data-pipeline-and-configuration-files-location/m-p/416161#M6124</link>
      <description>&lt;P&gt;One can specify sourcetype, index, source, and host in a UF, but since that where the data originates, I wouldn't call it an "override".  The rest of your statement is correct.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Jun 2019 22:59:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Knowledge-Management/data-pipeline-and-configuration-files-location/m-p/416161#M6124</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-06-08T22:59:43Z</dc:date>
    </item>
  </channel>
</rss>

