Getting Data In

Best Practice for Adding a Transforms on Indexers

dfurtaw
Path Finder

Hey Splunk world,

 

After learning that the nullQueue option for eliminating unneeded data is required to be installed on an indexer as a props/transforms combo vs. placing it on a UF.

 

I had one more question regarding this as I come into this roadblock quite a few times in our Splunk Cloud environment. Since we are on Splunk Cloud v 7.2, we run into rolling restarts on sourcetype additions and app installs. The way the folks in the admin realm have done things in the past is to add a props/transforms on a custom app, install it on the SH + Indexers and then allow those settings to globally apply across the environment on the specific sourcetype.

 

Is there a different way of implementing the below props/transforms combo into our environment without causing the rolling restart via app install? I usually add extractions via the GUI and this allows me to not cause a rollin restart, but with the format required for this data manipulation, I'm not sure if I'm able to use the GUI. Mainly wanting to save time and not wait until our Saturday maintenance window to make a change. Splunk Cloud does not allow access to the server CLI per SH or indexer.

PROPS

[linux_audit]
TRANSFORMS-null= setnull

TRANSFORMS

[setnull]
REGEX = type=CWD | key=\"delete\"
DEST_KEY = queue
FORMAT = nullQueue

Thank you!

Labels (3)

_smp_
Builder

I am a new Cloud customer myself, running Cloud version 2006. You have articulated a major problem I also have with Splunk Cloud. On-prem, the vast majority of config administration I performed did not require a rolling restart. Now in Splunk Cloud, just about everything I need to do incurs a rolling restart. This significantly extends the implementation timeline of every project, activity or fix. It is a major inconvenience and makes me question our decision to move to Cloud in the first place. Based on my initial experience, I am asking myself whether the administrative limitations enforced in Cloud were worth the trade. In the end I think handing off the search/index/storage infrastructure management will be worth it, but the transition from on-prem to Splunk Cloud is a nightmare. What a mess.

Tags (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

What’s New in Splunk AI: Volume 02

Welcome to the second edition of “What’s New in Splunk AI” where we look at the latest and greatest updates, ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Laser Bananas and Edge Hubs: Exploring Operational Technology (OT) Data Through a ...

  OT is a different environment to traditional IT and can have interesting challenges when interfacing the ...