If I want to use SEDCMD to rewrite values in my data, should it be configured on the forwarder or the indexer?
Thx.
Craig
If the forwarder is a heavy forwarder, full Splunk install, you can do it there. If not then you need to do it on the indexer.
I'm running Splunk 4.3.4. I'm finding that I need to define my line breaking rules and timestamp extraction on the forwarder. Doing it on the indexer doesn't work.
I stand corrected, it can be done on a lightweight forwarder.
http://splunk-base.splunk.com/answers/45411/rewrite-_raw-from-universal-forwarder-not-working