Knowledge Management

Why arent my props/transforms extracting

tkw03
Communicator

Hello

I have a field extraction set to extract headers from .txt files. I added the props and transforms to the indexers as well as the search heads but for some reason it isnt working.

 

My props on indexers and search heads:

[storage:data:updated]
CHARSET=UTF-8
DATETIME_CONFIG=CURRENT
LINE_BREAKER=([\r\n]+)
NO_BINARY_CHECK=null
SHOULD_LINEMERGE=false
disabled=false
pulldown_type=true
TRANSFORMS-splitfieldsv2 = storage-fieldsv2

And my transforms

[storage-fieldsv2]
CLEAN_KEYS = 0
REGEX = ^ *(?<Type>directory|file) +(?<AppliesTo>[^ ]+) +(?<Path>.+) +(?<Snap>[^ ]+) +(?<Hard>[^ ]+) +(?<Soft>[^ ]+) +(?<Adv>[^ ]+) +(?<Used>[^ ]+) +(?<Efficiency>\d+\.\d+\s\:\s\d+) *$

 

I know the extraction is right as I created by testing in my regex tester.

But for some reason this isnt working in testing. The only place I havent added this is to the UF since I was testing manually before adding tio the UF and sending the data? 

 

Any idea why this isnt working?

 

Hers a sample of the .txt file:

Type      AppliesTo  Path                             Snap  Hard    Soft  Adv    Used  Efficiency
--------------------------------------------------------------------------------------------------
directory DEFAULT    /ifs/data/stuff/T1000-Reports No    100.00M -     99.00M 53.00 0.00 : 1
--------------------------------------------------------------------------------------------------
Total: 1

Thanks for the assistance

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Did you restart the indexers and search heads after modifying the config files?

---
If this reply helps you, Karma would be appreciated.
0 Karma

tkw03
Communicator

Well, I pushed the apps via the Cluster Masters(SH and indexer) So I would assume it restarted as necessary. I'll rolling restart my test env to make sure though.

0 Karma

tkw03
Communicator

Restart was not the issue

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...