I have a Splunk 6.2.0 multisite cluster setup. Per site, there is one indexer, one search head and a master. I am pulling logs from a client on Windows using splunk universal forwarder, but I need to change the Line Break. I have defined a new sourcetype in props.conf and placed it on the client and restarted the splunkd on the client. I still don't see the changes when I search the data on the search head.
Do I have to define the sourcetype on the indexer as well? or just the indexer and not in the client?
Thanks
Hello
The parsing stage happens in the indexers (or Heavy Forwarders) not in the Universal Forwarder
So that props must be placed in the indexers, in your case as you are using a cluster, then you need to deploy it through the cluster master, using master apps, and the apply cluster bundle command
Regards
Hello
The parsing stage happens in the indexers (or Heavy Forwarders) not in the Universal Forwarder
So that props must be placed in the indexers, in your case as you are using a cluster, then you need to deploy it through the cluster master, using master apps, and the apply cluster bundle command
Regards