Getting Data In

Where do INDEXED_EXTRACTIONS happen?

joxley
Path Finder

I have a Universal Forwarder reading data in a Tab Separated format. I want to apply the INDEXED_EXTRACTIONS = TSV to it.

Do I need to put that on the Indexer or the Forwarder?

A further question is that if the file is being appended to and the top line contains the headers, do I have to wait for the file to be rotated before I'll get the field extractions?

1 Solution

woodcock
Esteemed Legend

You have to put this on every Forwarder and then restart all splunk instances there; read about this caveat here:

http://docs.splunk.com/Documentation/Splunk/6.0/Data/Extractfieldsfromfileheadersatindextime#Caveats

View solution in original post

woodcock
Esteemed Legend

You have to put this on every Forwarder and then restart all splunk instances there; read about this caveat here:

http://docs.splunk.com/Documentation/Splunk/6.0/Data/Extractfieldsfromfileheadersatindextime#Caveats

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Build the Future of Agentic AI: Join the Splunk Agentic Ops Hackathon

AI is changing how teams investigate incidents, detect threats, automate workflows, and build intelligent ...

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...