Getting Data In

Why is indexed extraction not happening when the data comes via the UF?

koshyk
Super Champion

Hi,

We have a quite a "piggy backed" data coming from a system and extracting as

[mysourcetype]
SHOULD_LINEMERGE=false
INDEXED_EXTRACTIONS=CSV
FIELD_NAMES=Date,Time,EmployeeID,EmployeeName
TIMESTAMP_FIELDS=Date,Time

(A) System Data collected using UF => (B) Sent to Heavy Forwarder => (C) HF to Indexer => (D) Clustered SH

We have the

  • inputs.conf in (A)
  • props.conf with INDEXED_EXTRACTIONS=CSV in (B) , (C) & (D)

Directly indexing the file works perfectly in standalone Splunk Instance.
But when the data comes via the UF, the indexed extraction is not happening.

Any reasons for this? Should we add props.conf to UF?

0 Karma
1 Solution

marthodder
Explorer

You're correct - You will need to add INDEXED_EXTRACTIONS=CSV in a props.conf for local deployment to each of the hosts.

[sourcetype] 
INDEXED_EXTRACTIONS=CSV

View solution in original post

marthodder
Explorer

You're correct - You will need to add INDEXED_EXTRACTIONS=CSV in a props.conf for local deployment to each of the hosts.

[sourcetype] 
INDEXED_EXTRACTIONS=CSV

koshyk
Super Champion

thanks for the tip.
UF also requires the props.conf

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...