All Apps and Add-ons

Extracting host from events - Multiple Indexers

jakesony
Explorer

I am trying to extract and override the 'host' field value from events. I have it working on one indexer in a three indexer group of peers. I am using UFs which load balance between three indexers (call them Indexer1, Indexer2, and Indexer3).

I have edited props and transforms.conf on Indexer1. When events happen to be forwarded to Indexer1, the value of host in the events is correct (meaning extracted from the event). When an event is forwarded to either Indexer2 or Indexer3 the host is that of the box that the forwarder is on (meaning not extracted from the event).

I'm guessing that I need to edit props and transfomers.conf on Indexer2 and Indexer3, however, I have not needed to edit (or even create) these on these indexers. For example, when I create a new sourcetype, I do it only on Indexer1 but Indexer2 and Indexer3 correctly identify the sourcetype without having to add it to each (perhaps because the forward is dictating the souretype value?).

So, my question is, where and how should I edit the configuration in order for the host field to be correctly extracted from event data for a given source type when using multiple indexers load balanced by the forwarder? If I need to maintain props.conf and transforms.conf on all three indexers, what is the best practice for doing so? Should I simply copy the files from Indexer1 to Indexer2 and Indexer3?

Thanks!

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

Best practice for maintaining identical configurations on multiple indexers is to either use configuration bundles distributed by the master in a clustered environment, or to distribute a configuration app through a deployment server in a non-clustered environment.

View solution in original post

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

Best practice for maintaining identical configurations on multiple indexers is to either use configuration bundles distributed by the master in a clustered environment, or to distribute a configuration app through a deployment server in a non-clustered environment.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...