Getting Data In

Best Practice for Adding a Transforms on Indexers

dfurtaw
Path Finder

Hey Splunk world,

 

After learning that the nullQueue option for eliminating unneeded data is required to be installed on an indexer as a props/transforms combo vs. placing it on a UF.

 

I had one more question regarding this as I come into this roadblock quite a few times in our Splunk Cloud environment. Since we are on Splunk Cloud v 7.2, we run into rolling restarts on sourcetype additions and app installs. The way the folks in the admin realm have done things in the past is to add a props/transforms on a custom app, install it on the SH + Indexers and then allow those settings to globally apply across the environment on the specific sourcetype.

 

Is there a different way of implementing the below props/transforms combo into our environment without causing the rolling restart via app install? I usually add extractions via the GUI and this allows me to not cause a rollin restart, but with the format required for this data manipulation, I'm not sure if I'm able to use the GUI. Mainly wanting to save time and not wait until our Saturday maintenance window to make a change. Splunk Cloud does not allow access to the server CLI per SH or indexer.

PROPS

[linux_audit]
TRANSFORMS-null= setnull

TRANSFORMS

[setnull]
REGEX = type=CWD | key=\"delete\"
DEST_KEY = queue
FORMAT = nullQueue

Thank you!

Labels (3)

_smp_
Builder

I am a new Cloud customer myself, running Cloud version 2006. You have articulated a major problem I also have with Splunk Cloud. On-prem, the vast majority of config administration I performed did not require a rolling restart. Now in Splunk Cloud, just about everything I need to do incurs a rolling restart. This significantly extends the implementation timeline of every project, activity or fix. It is a major inconvenience and makes me question our decision to move to Cloud in the first place. Based on my initial experience, I am asking myself whether the administrative limitations enforced in Cloud were worth the trade. In the end I think handing off the search/index/storage infrastructure management will be worth it, but the transition from on-prem to Splunk Cloud is a nightmare. What a mess.

Tags (1)
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Defend at Machine Speed: Your Guide to Security Sessions at .conf26

Splunk .conf26   With threats moving at machine speed and attack surfaces expanding across hybrid ...

Where Innovation Takes Flight: The Splunk4Aviation Flight Sim Lands at .conf26

If you hear someone at .conf26 shouting "gear down, GEAR DOWN" across the show floor, you have found us.  The ...

Turn Cisco Telemetry Into Action with Cisco Data Fabric, powered by the Splunk ...

The surge in machine data is already hitting enterprise budgets, and the agentic era will only intensify it. ...