Knowledge Management

Why arent my props/transforms extracting

tkw03
Communicator

Hello

I have a field extraction set to extract headers from .txt files. I added the props and transforms to the indexers as well as the search heads but for some reason it isnt working.

 

My props on indexers and search heads:

[storage:data:updated]
CHARSET=UTF-8
DATETIME_CONFIG=CURRENT
LINE_BREAKER=([\r\n]+)
NO_BINARY_CHECK=null
SHOULD_LINEMERGE=false
disabled=false
pulldown_type=true
TRANSFORMS-splitfieldsv2 = storage-fieldsv2

And my transforms

[storage-fieldsv2]
CLEAN_KEYS = 0
REGEX = ^ *(?<Type>directory|file) +(?<AppliesTo>[^ ]+) +(?<Path>.+) +(?<Snap>[^ ]+) +(?<Hard>[^ ]+) +(?<Soft>[^ ]+) +(?<Adv>[^ ]+) +(?<Used>[^ ]+) +(?<Efficiency>\d+\.\d+\s\:\s\d+) *$

 

I know the extraction is right as I created by testing in my regex tester.

But for some reason this isnt working in testing. The only place I havent added this is to the UF since I was testing manually before adding tio the UF and sending the data? 

 

Any idea why this isnt working?

 

Hers a sample of the .txt file:

Type      AppliesTo  Path                             Snap  Hard    Soft  Adv    Used  Efficiency
--------------------------------------------------------------------------------------------------
directory DEFAULT    /ifs/data/stuff/T1000-Reports No    100.00M -     99.00M 53.00 0.00 : 1
--------------------------------------------------------------------------------------------------
Total: 1

Thanks for the assistance

Labels (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

Did you restart the indexers and search heads after modifying the config files?

---
If this reply helps you, Karma would be appreciated.
0 Karma

tkw03
Communicator

Well, I pushed the apps via the Cluster Masters(SH and indexer) So I would assume it restarted as necessary. I'll rolling restart my test env to make sure though.

0 Karma

tkw03
Communicator

Restart was not the issue

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...