Deployment Architecture

Unable to push the config from cluster master

syedabuthahir
Explorer

Hi All,

 

We are trying to push the props and transforms config files from Cluster Master to all indexers. Source types are visible but the rules are not applied from the config files.

Please assist on this issue.

Thanks in Advance.

Labels (1)
0 Karma

codebuilder
Influencer

Are you saying the configs dont get pushed from the master or they are not applied?

Most extractions are done at search time, not index time. For search time extractions, your configs would need to go to the search heads, not the indexers.

https://docs.splunk.com/Documentation/Splunk/8.2.1/Indexer/Indextimeversussearchtime

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

isoutamo
SplunkTrust
SplunkTrust
If you are added new extractions etc. for indexers then those are valid only when new data has indexed not for old already indexed events.
As @codebuilder said for search time props + transforms conf must be on SH side not on Indexer side. Also remember add fields.conf to SH side if/when you have any additional indexed fields.
r. Ismo
0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

(view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...