I have a log file on a windows forwarder for which - I want to segregate the fields contained in that log file -- on the forwarder -- before they are pickedup by the indexer.
The configuration at : C:\Program Files\SplunkUniversalForwarder\etc\system\local\ is like this:
>>inputs.conf:
[monitor ://D\Folder]
disabled=0
whitelist=Organization\.csv*
index=main
sourcetype=alpha
This works UP TILL THIS POINT - as in - searching for sourcetype=alpha gives us properly indexed content of Organization.log
The next and the more painful step is to correctly configure the props.conf and transforms.conf [neither of which exist under C:\Program Files\SplunkUniversalForwarder\etc\system\local\ - SO I HAD TO ADD THEM]
>> props.conf:
[alpha]
REPORT-alpha = alpha-fields
>> transforms.conf:
[alpha-fields]
DELIMS=","
FIELDS="field1-alpha", "field2-alpha"
This does not work.
Any ideas ?
"REPORT" is a search time extraction , so your props.conf and transforms.conf should live on your Splunk Search Head , not the Universal Forwarder.
"REPORT" is a search time extraction , so your props.conf and transforms.conf should live on your Splunk Search Head , not the Universal Forwarder.
These are again the changes we made and their locations:
On the FORWARDER (Windows Machine) - inputs.conf - changed at :
\etc\system\local\
--
On the INDEXER (Search Head) - we added the following to props.conf at C:\Program Files\Splunk\etc\system\local\
C:\Program Files\SplunkUniversalForwarder\etc\system\local\
[alpha]
CHECK_FOR_HEADER=true
KV_MODE=none
NO_BINARY_CHECK=1
SHOULD_LINEMERGE=false
--
On the INDEXER (Search Head) - we added a second props.conf and transforms.conf (from my initial post) at
C:\Program Files\Splunk\etc\apps\search\local\
Thanks damien !
That did not seem to work out for us 😞
For the particular configuration you have described in your original post :
inputs.conf -> Universal Forwarder
props.conf & transforms.conf -> Splunk Search Head
Does it matter that the configuration to capture this sourcetype is done on the forwarder side ?
We changed the inputs.conf on the forwarder side
Shouldnt the props.conf and transforms.conf also live on the forwarder side ?