Getting Data In

Props and Transforms doubt

Karthikeya
Communicator

I am new to Splunk admin and please explain this following stanzas:

We have a dedicated syslog server which receives the logs from network devices and UF installed on the server forwards the data to our cluster manager. These configs are in cluster manager under manager apps.

0 Karma

Karthikeya
Communicator

Thank you @sainag_splunk ..

Then what about inputs.conf and outputs.conf (i believe it will not be there considering it's indexer) in indexer cluster should be configured?

We have deployment server as well. Can you please let me know where it will be there in picture?

sainag_splunk
Splunk Employee
Splunk Employee
  1. Data Flow:

Data goes DIRECTLY from UF to indexers on port 9997 (not to cluster manager)

Cluster Manager only handles configuration distribution

  1. Configuration Management:

Props and transforms configs are deployed via cluster manager

These configs are pushed to index peers via index cluster bundle

  1. Processing Location:

All parsing happens on the indexers (index peers)

Each indexer applies the deployed configurations independently

For Deep Understanding: Refer: https://community.splunk.com/t5/Getting-Data-In/Diagrams-of-how-indexing-works-in-the-Splunk-platfor...

  • Review props.conf documentation: docs.splunk.com/Documentation/Splunk/9.1.0/Admin/Propsconf
  •  docs.splunk.com/Documentation/ITSI/4.17.0/Configure/transforms.conf

Since there are many pipeline components, I encourage you to read through these resources for a complete understanding.

Simple Data Flow here.

Screenshot 2024-11-12 at 5.55.15 PM.png



If this Helps, Please Upvote.

If this helps, Upvote!!!!
Together we make the Splunk Community stronger 

Karthikeya
Communicator

Hi @sainag_splunk ,

Also please explain what is index peers you mean and index cluster bundle?

Please reply

0 Karma

sainag_splunk
Splunk Employee
Splunk Employee

@Karthikeya Index peers are simply indexers that work together in a Splunk cluster environment. They are responsible for receiving, processing, and storing data while maintaining copies across multiple indexers for redundancy and high availability. When a Cluster Master pushes configuration changes through an index cluster bundle, all index peers receive the same settings to ensure consistent operation across the cluster.

Refer: https://docs.splunk.com/Documentation/Splunk/9.3.2/Indexer/Basicclusterarchitecture
https://docs.splunk.com/Documentation/Splunk/9.3.2/Indexer/Howclusteredindexingworks



If this Helps, Please Upvote and Mark as solved.

Screenshot 2024-11-18 at 10.30.11 AM.png

If this helps, Upvote!!!!
Together we make the Splunk Community stronger 
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...