Getting Data In

Index time fields ignored in cluster

charltones
Explorer

I have a cluster setup with search head, master, 3 indexers and a forwarder. The index config is pushed from the master (and I can see after splunk apply cluster-bundle) that it successfully turns up on each index node. The problem is that all the index time transforms I have entered are being ignored.

I have the same symptoms as this question (http://answers.splunk.com/answers/93776/push-configuration-files-in-cluster) but my fields are extracted at index time. I successfully applied the same config (or at least I thought it was the same) on a separate cluster and that worked fine. Can anyone point me in the right direction to debug why the transforms are not being applied?

Similar also to this issue: http://answers.splunk.com/answers/118649/index-time-props-and-transforms-not-working

Splunk Enterprise 6.1

0 Karma
1 Solution

charltones
Explorer

I think the answer is that either:

  1. This doesn't work - you can't have index time fields carried out by indexers in a cluster or
  2. It is because I was using a heavy forwarder - i.e. it believed the indexing work had already been done.

I didn't realise I was using a heavy forwarder, but I've fixed my problem by moving the indexing config to the forwarder instead and it is all behaving as expected now

View solution in original post

0 Karma

charltones
Explorer

I think the answer is that either:

  1. This doesn't work - you can't have index time fields carried out by indexers in a cluster or
  2. It is because I was using a heavy forwarder - i.e. it believed the indexing work had already been done.

I didn't realise I was using a heavy forwarder, but I've fixed my problem by moving the indexing config to the forwarder instead and it is all behaving as expected now

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...