Deployment Architecture

Where to perform field extraction in Splunk cluster

neltonk
Path Finder

Hi, I am new to Splunk. I have built a splunk cluster (3 indexers, 1 master(also the license master), 1 search head).
I have deployed universal forwarders to all the servers using ansible and I am getting the data that I require. However I am not sure where do I now extract fields - in the indexers or search head?

Please advice...

Thanks,
Nelton

FrankVl
Ultra Champion

Field extractions are configured on the Search Head, since they happen at search time.

Unless you have any specific need to perform index time extractions (e.g. to override the host / sourcetype). Those would have to be set on the indexers.

neltonk
Path Finder

Thanks a lot for your quick response... if I have to override the host field, do I have to do the field extraction on each indexer? Please let me know.

0 Karma

FrankVl
Ultra Champion

Best is to create a small app, that contains the relevant props.conf and transforms.conf and push that to all indexers in the cluster from the cluster master.
http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Updatepeerconfigurations

0 Karma

neltonk
Path Finder

And when done on indexer, will I be using the splunk web to do this or should this be done using props.conf.
Thanks,Nelton

0 Karma
Get Updates on the Splunk Community!

Splunk Cloud | Empowering Splunk Administrators with Admin Config Service (ACS)

Greetings, Splunk Cloud Admins and Splunk enthusiasts! The Admin Configuration Service (ACS) team is excited ...

Tech Talk | One Log to Rule Them All

One log to rule them all: how you can centralize your troubleshooting with Splunk logs We know how important ...

Splunk Security Content for Threat Detection & Response, Q1 Roundup

Join Principal Threat Researcher, Michael Haag, as he walks through:An introduction to the Splunk Threat ...