Deployment Architecture

Question about props.conf and light forwarders

responsys_cm
Builder

If I want to use SEDCMD to rewrite values in my data, should it be configured on the forwarder or the indexer?

Thx.

Craig

Tags (1)
0 Karma

jgedeon120
Contributor

If the forwarder is a heavy forwarder, full Splunk install, you can do it there. If not then you need to do it on the indexer.

responsys_cm
Builder

I'm running Splunk 4.3.4. I'm finding that I need to define my line breaking rules and timestamp extraction on the forwarder. Doing it on the indexer doesn't work.

0 Karma

jgedeon120
Contributor

I stand corrected, it can be done on a lightweight forwarder.

http://splunk-base.splunk.com/answers/45411/rewrite-_raw-from-universal-forwarder-not-working

0 Karma
Get Updates on the Splunk Community!

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...