Deployment Architecture

Unable to push the config from cluster master

syedabuthahir
Explorer

Hi All,

 

We are trying to push the props and transforms config files from Cluster Master to all indexers. Source types are visible but the rules are not applied from the config files.

Please assist on this issue.

Thanks in Advance.

Labels (1)
0 Karma

codebuilder
Influencer

Are you saying the configs dont get pushed from the master or they are not applied?

Most extractions are done at search time, not index time. For search time extractions, your configs would need to go to the search heads, not the indexers.

https://docs.splunk.com/Documentation/Splunk/8.2.1/Indexer/Indextimeversussearchtime

----
An upvote would be appreciated and Accept Solution if it helps!
0 Karma

isoutamo
SplunkTrust
SplunkTrust
If you are added new extractions etc. for indexers then those are valid only when new data has indexed not for old already indexed events.
As @codebuilder said for search time props + transforms conf must be on SH side not on Indexer side. Also remember add fields.conf to SH side if/when you have any additional indexed fields.
r. Ismo
0 Karma
Get Updates on the Splunk Community!

Join Us for Splunk University and Get Your Bootcamp Game On!

If you know, you know! Splunk University is the vibe this summer so register today for bootcamps galore ...

.conf24 | Learning Tracks for Security, Observability, Platform, and Developers!

.conf24 is taking place at The Venetian in Las Vegas from June 11 - 14. Continue reading to learn about the ...

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...