Getting Data In

Forwarder configuration

asarolkar
Builder

I have a log file on a windows forwarder for which - I want to segregate the fields contained in that log file -- on the forwarder -- before they are pickedup by the indexer.

The configuration at : C:\Program Files\SplunkUniversalForwarder\etc\system\local\ is like this:

>>inputs.conf:
[monitor ://D\Folder]
disabled=0
whitelist=Organization\.csv*
index=main
sourcetype=alpha

This works UP TILL THIS POINT - as in - searching for sourcetype=alpha gives us properly indexed content of Organization.log

The next and the more painful step is to correctly configure the props.conf and transforms.conf [neither of which exist under C:\Program Files\SplunkUniversalForwarder\etc\system\local\ - SO I HAD TO ADD THEM]

>> props.conf:
[alpha]
REPORT-alpha = alpha-fields

>> transforms.conf:
[alpha-fields]
DELIMS=","
FIELDS="field1-alpha", "field2-alpha"

This does not work.

Any ideas ?

0 Karma
1 Solution

Damien_Dallimor
Ultra Champion

"REPORT" is a search time extraction , so your props.conf and transforms.conf should live on your Splunk Search Head , not the Universal Forwarder.

View solution in original post

0 Karma

Damien_Dallimor
Ultra Champion

"REPORT" is a search time extraction , so your props.conf and transforms.conf should live on your Splunk Search Head , not the Universal Forwarder.

0 Karma

asarolkar
Builder

These are again the changes we made and their locations:

On the FORWARDER (Windows Machine) - inputs.conf - changed at :

\etc\system\local\

--

On the INDEXER (Search Head) - we added the following to props.conf at C:\Program Files\Splunk\etc\system\local\

C:\Program Files\SplunkUniversalForwarder\etc\system\local\
[alpha]
CHECK_FOR_HEADER=true
KV_MODE=none
NO_BINARY_CHECK=1
SHOULD_LINEMERGE=false

--

On the INDEXER (Search Head) - we added a second props.conf and transforms.conf (from my initial post) at

C:\Program Files\Splunk\etc\apps\search\local\

0 Karma

asarolkar
Builder

Thanks damien !

That did not seem to work out for us 😞

0 Karma

Damien_Dallimor
Ultra Champion

For the particular configuration you have described in your original post :

inputs.conf -> Universal Forwarder
props.conf & transforms.conf -> Splunk Search Head

asarolkar
Builder

Does it matter that the configuration to capture this sourcetype is done on the forwarder side ?

We changed the inputs.conf on the forwarder side

Shouldnt the props.conf and transforms.conf also live on the forwarder side ?

0 Karma
Get Updates on the Splunk Community!

Upcoming Webinar: Unmasking Insider Threats with Slunk Enterprise Security’s UEBA

Join us on Wed, Dec 10. at 10AM PST / 1PM EST for a live webinar and demo with Splunk experts! Discover how ...

.conf25 technical session recap of Observability for Gen AI: Monitoring LLM ...

If you’re unfamiliar, .conf is Splunk’s premier event where the Splunk community, customers, partners, and ...

A Season of Skills: New Splunk Courses to Light Up Your Learning Journey

There’s something special about this time of year—maybe it’s the glow of the holidays, maybe it’s the ...