All Apps and Add-ons

Extracting host from events - Multiple Indexers

jakesony
Explorer

I am trying to extract and override the 'host' field value from events. I have it working on one indexer in a three indexer group of peers. I am using UFs which load balance between three indexers (call them Indexer1, Indexer2, and Indexer3).

I have edited props and transforms.conf on Indexer1. When events happen to be forwarded to Indexer1, the value of host in the events is correct (meaning extracted from the event). When an event is forwarded to either Indexer2 or Indexer3 the host is that of the box that the forwarder is on (meaning not extracted from the event).

I'm guessing that I need to edit props and transfomers.conf on Indexer2 and Indexer3, however, I have not needed to edit (or even create) these on these indexers. For example, when I create a new sourcetype, I do it only on Indexer1 but Indexer2 and Indexer3 correctly identify the sourcetype without having to add it to each (perhaps because the forward is dictating the souretype value?).

So, my question is, where and how should I edit the configuration in order for the host field to be correctly extracted from event data for a given source type when using multiple indexers load balanced by the forwarder? If I need to maintain props.conf and transforms.conf on all three indexers, what is the best practice for doing so? Should I simply copy the files from Indexer1 to Indexer2 and Indexer3?

Thanks!

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Best practice for maintaining identical configurations on multiple indexers is to either use configuration bundles distributed by the master in a clustered environment, or to distribute a configuration app through a deployment server in a non-clustered environment.

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Best practice for maintaining identical configurations on multiple indexers is to either use configuration bundles distributed by the master in a clustered environment, or to distribute a configuration app through a deployment server in a non-clustered environment.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...