Deployment Architecture

Props and transforms stopped working on search heads


I'm using the Splunk_TA_infoblox add-on in two ways:

  1. A modified version (with an added TRANSFORMS-1_branch_index) on the indexer cluster to split data into 2 indexes;
  2. The original version on a search head cluster to extract all the fields.

The TA was originally deployed without the part 1 above. That worked fine. But now with part 1 deployed, part 2 seems to have stopped working.

When search for "index=ipam_secure sourcetype=infoblox:dns", for example, I get events back but no field extractions.

Since the [infoblox:dns] stanza is unchanged on the search heads, I am puzzled as why the props and transforms stopped working. Any pointers would be much appreciated!

0 Karma
.conf21 Now Fully Virtual!
Register for FREE Today!

We've made .conf21 totally virtual and totally FREE! Our completely online experience will run from 10/19 through 10/20 with some additional events, too!