Deployment Architecture

Unable to push the config from cluster master

syedabuthahir
Explorer

Hi All,

 

We are trying to push the props and transforms config files from Cluster Master to all indexers. Source types are visible but the rules are not applied from the config files.

Please assist on this issue.

Thanks in Advance.

Labels (1)
0 Karma

codebuilder
Influencer

Are you saying the configs dont get pushed from the master or they are not applied?

Most extractions are done at search time, not index time. For search time extractions, your configs would need to go to the search heads, not the indexers.

https://docs.splunk.com/Documentation/Splunk/8.2.1/Indexer/Indextimeversussearchtime

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

isoutamo
SplunkTrust
SplunkTrust
If you are added new extractions etc. for indexers then those are valid only when new data has indexed not for old already indexed events.
As @codebuilder said for search time props + transforms conf must be on SH side not on Indexer side. Also remember add fields.conf to SH side if/when you have any additional indexed fields.
r. Ismo
0 Karma
Get Updates on the Splunk Community!

Earn a $35 Gift Card for Answering our Splunk Admins & App Developer Survey

Survey for Splunk Admins and App Developers is open now! | Earn a $35 gift card!      Hello there,  Splunk ...

Continuing Innovation & New Integrations Unlock Full Stack Observability For Your ...

You’ve probably heard the latest about AppDynamics joining the Splunk Observability portfolio, deepening our ...

Monitoring Amazon Elastic Kubernetes Service (EKS)

As we’ve seen, integrating Kubernetes environments with Splunk Observability Cloud is a quick and easy way to ...