Hi All,
We are trying to push the props and transforms config files from Cluster Master to all indexers. Source types are visible but the rules are not applied from the config files.
Please assist on this issue.
Thanks in Advance.
Are you saying the configs dont get pushed from the master or they are not applied?
Most extractions are done at search time, not index time. For search time extractions, your configs would need to go to the search heads, not the indexers.
https://docs.splunk.com/Documentation/Splunk/8.2.1/Indexer/Indextimeversussearchtime