Deployment Architecture

Props and transforms stopped working on search heads

ww9rivers
Contributor

I'm using the Splunk_TA_infoblox add-on in two ways:

  1. A modified version (with an added TRANSFORMS-1_branch_index) on the indexer cluster to split data into 2 indexes;
  2. The original version on a search head cluster to extract all the fields.

The TA was originally deployed without the part 1 above. That worked fine. But now with part 1 deployed, part 2 seems to have stopped working.

When search for "index=ipam_secure sourcetype=infoblox:dns", for example, I get events back but no field extractions.

Since the [infoblox:dns] stanza is unchanged on the search heads, I am puzzled as why the props and transforms stopped working. Any pointers would be much appreciated!

0 Karma
Get Updates on the Splunk Community!

Splunk Decoded: Service Maps vs Service Analyzer Tree View vs Flow Maps

It’s Monday morning, and your phone is buzzing with alert escalations – your customer-facing portal is running ...

What’s New in Splunk Observability – September 2025

What's NewWe are excited to announce the latest enhancements to Splunk Observability, designed to help ITOps ...

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...