Getting Data In

Where do Report extractions go

a212830
Champion

Hi,

I have some access logs and want to use the provided out-of-the-box field extractions (access-extractions). I am using a custom named sourcetype. I've put the props and transforms on the indexer, but I'm still not seeing them. Do they need to go on the search-head?

0 Karma

MuS
SplunkTrust
SplunkTrust

Hi a212830,

check out this wiki http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings and have a closer look at the props.conf in the parsing and the search section. Depending on your config it will either be the indexer or the search head.

hope this helps ...

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Unlock Database Monitoring with Splunk Observability Cloud

  In today’s fast-paced digital landscape, even minor database slowdowns can disrupt user experiences and ...

Purpose in Action: How Splunk Is Helping Power an Inclusive Future for All

At Cisco, purpose isn’t a tagline—it’s a commitment. Cisco’s FY25 Purpose Report outlines how the company is ...

[Upcoming Webinar] Demo Day: Transforming IT Operations with Splunk

Join us for a live Demo Day at the Cisco Store on January 21st 10:00am - 11:00am PST In the fast-paced world ...