Deployment Architecture

Unable to push the config from cluster master

syedabuthahir
Explorer

Hi All,

 

We are trying to push the props and transforms config files from Cluster Master to all indexers. Source types are visible but the rules are not applied from the config files.

Please assist on this issue.

Thanks in Advance.

Labels (1)
0 Karma

codebuilder
Influencer

Are you saying the configs dont get pushed from the master or they are not applied?

Most extractions are done at search time, not index time. For search time extractions, your configs would need to go to the search heads, not the indexers.

https://docs.splunk.com/Documentation/Splunk/8.2.1/Indexer/Indextimeversussearchtime

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

isoutamo
SplunkTrust
SplunkTrust
If you are added new extractions etc. for indexers then those are valid only when new data has indexed not for old already indexed events.
As @codebuilder said for search time props + transforms conf must be on SH side not on Indexer side. Also remember add fields.conf to SH side if/when you have any additional indexed fields.
r. Ismo
0 Karma
Get Updates on the Splunk Community!

Splunk Observability for AI

Don’t miss out on an exciting Tech Talk on Splunk Observability for AI!Discover how Splunk’s agentic AI ...

Splunk Enterprise Security 8.x: The Essential Upgrade for Threat Detection, ...

Watch On Demand the Tech Talk on November 6 at 11AM PT, and empower your SOC to reach new heights! Duration: ...

Splunk Observability as Code: From Zero to Dashboard

For the details on what Self-Service Observability and Observability as Code is, we have some awesome content ...