Deployment Architecture

Question about props.conf and light forwarders

responsys_cm
Builder

If I want to use SEDCMD to rewrite values in my data, should it be configured on the forwarder or the indexer?

Thx.

Craig

Tags (1)
0 Karma

jgedeon120
Contributor

If the forwarder is a heavy forwarder, full Splunk install, you can do it there. If not then you need to do it on the indexer.

responsys_cm
Builder

I'm running Splunk 4.3.4. I'm finding that I need to define my line breaking rules and timestamp extraction on the forwarder. Doing it on the indexer doesn't work.

0 Karma

jgedeon120
Contributor

I stand corrected, it can be done on a lightweight forwarder.

http://splunk-base.splunk.com/answers/45411/rewrite-_raw-from-universal-forwarder-not-working

0 Karma
Get Updates on the Splunk Community!

Demo Day: Strengthen Your SOC with Splunk Enterprise Security 8.1

Today’s threat landscape is more complex than ever. Security operation centers (SOCs) are overwhelmed with ...

Dashboards: Hiding charts while search is being executed and other uses for tokens

There are a couple of features of SimpleXML / Classic dashboards that can be used to enhance the user ...

Splunk Observability Cloud's AI Assistant in Action Series: Explaining Metrics and ...

This is the fourth post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how ...