<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Index time SEDCMD not applying when indexer is split from search head in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Index-time-SEDCMD-not-applying-when-indexer-is-split-from-search/m-p/101754#M26287</link>
    <description>&lt;P&gt;As with &lt;A href="http://splunk-base.splunk.com/answers/11680/sedcmd-not-executing"&gt;http://splunk-base.splunk.com/answers/11680/sedcmd-not-executing&lt;/A&gt;, if there is a heavy forwarder processing the data before the indexer, the SEDCMD and other parsing happens there. &lt;/P&gt;

&lt;P&gt;See &lt;A href="http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings"&gt;http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings&lt;/A&gt; for more details&lt;/P&gt;</description>
    <pubDate>Thu, 19 Jul 2012 01:43:54 GMT</pubDate>
    <dc:creator>willthames2</dc:creator>
    <dc:date>2012-07-19T01:43:54Z</dc:date>
    <item>
      <title>Index time SEDCMD not applying when indexer is split from search head</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Index-time-SEDCMD-not-applying-when-indexer-is-split-from-search/m-p/101752#M26285</link>
      <description>&lt;P&gt;I have a configuration working perfectly in development in an environment with a single Splunk instance.&lt;/P&gt;

&lt;P&gt;This is the relevant part of &lt;CODE&gt;props.conf&lt;/CODE&gt;, which we've put on the indexer so that the index-time transformation will be performed:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[host::DoubleClick]
SEDCMD-01_DoubleClickDelimSpacer = y/þ/, /
[mysourcetype1]
CHARSET = ISO-8859-1
[mysourcetype2]
CHARSET = ISO-8859-1
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The &lt;CODE&gt;SEDCMD&lt;/CODE&gt; is not working at all - the data is not being transformed. As I said, if I do this in an environment where the search head and the indexer are one and the same, and all my search-time field extractions are in the same &lt;CODE&gt;props.conf&lt;/CODE&gt; as the above, everything works.&lt;/P&gt;

&lt;P&gt;The &lt;CODE&gt;CHARSET&lt;/CODE&gt; must be set correctly for Splunk to read the file correctly; I tried specifying it in the host stanza with the &lt;CODE&gt;SEDCMD&lt;/CODE&gt; and it didn't help.&lt;/P&gt;

&lt;P&gt;The production environment is running &lt;CODE&gt;4.3.0&lt;/CODE&gt;, while the dev environment is running &lt;CODE&gt;4.3.2&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;Anyone got any tips?&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2012 03:58:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Index-time-SEDCMD-not-applying-when-indexer-is-split-from-search/m-p/101752#M26285</guid>
      <dc:creator>dbryan</dc:creator>
      <dc:date>2012-07-18T03:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Index time SEDCMD not applying when indexer is split from search head</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Index-time-SEDCMD-not-applying-when-indexer-is-split-from-search/m-p/101753#M26286</link>
      <description>&lt;P&gt;Cracked it - looks like the character encoding had to be set on the forwarder, rather than on the indexer. I created a props.conf on the forwarder and set it in there and everything worked. Strange that the encoding handling is done on the forwarder when it's not doing any indexing.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jul 2012 07:16:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Index-time-SEDCMD-not-applying-when-indexer-is-split-from-search/m-p/101753#M26286</guid>
      <dc:creator>dbryan</dc:creator>
      <dc:date>2012-07-18T07:16:23Z</dc:date>
    </item>
    <item>
      <title>Re: Index time SEDCMD not applying when indexer is split from search head</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Index-time-SEDCMD-not-applying-when-indexer-is-split-from-search/m-p/101754#M26287</link>
      <description>&lt;P&gt;As with &lt;A href="http://splunk-base.splunk.com/answers/11680/sedcmd-not-executing"&gt;http://splunk-base.splunk.com/answers/11680/sedcmd-not-executing&lt;/A&gt;, if there is a heavy forwarder processing the data before the indexer, the SEDCMD and other parsing happens there. &lt;/P&gt;

&lt;P&gt;See &lt;A href="http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings"&gt;http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings&lt;/A&gt; for more details&lt;/P&gt;</description>
      <pubDate>Thu, 19 Jul 2012 01:43:54 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Index-time-SEDCMD-not-applying-when-indexer-is-split-from-search/m-p/101754#M26287</guid>
      <dc:creator>willthames2</dc:creator>
      <dc:date>2012-07-19T01:43:54Z</dc:date>
    </item>
  </channel>
</rss>

