Hi,
We have a quite a "piggy backed" data coming from a system and extracting as
[mysourcetype]
SHOULD_LINEMERGE=false
INDEXED_EXTRACTIONS=CSV
FIELD_NAMES=Date,Time,EmployeeID,EmployeeName
TIMESTAMP_FIELDS=Date,Time
(A) System Data collected using UF => (B) Sent to Heavy Forwarder => (C) HF to Indexer => (D) Clustered SH
We have the
Directly indexing the file works perfectly in standalone Splunk Instance.
But when the data comes via the UF, the indexed extraction is not happening.
Any reasons for this? Should we add props.conf to UF?
You're correct - You will need to add INDEXED_EXTRACTIONS=CSV in a props.conf for local deployment to each of the hosts.
[sourcetype]
INDEXED_EXTRACTIONS=CSV
You're correct - You will need to add INDEXED_EXTRACTIONS=CSV in a props.conf for local deployment to each of the hosts.
[sourcetype]
INDEXED_EXTRACTIONS=CSV
thanks for the tip.
UF also requires the props.conf