Splunk Enterprise Security

Splunk ES indexer deployment

brianmarc
New Member

I see some apps that state they need to be deployed to indexers. However I see no usage of the “TRANSFORMS-” in the props.conf for the app. Is this an error in the README file or an error in my assessment of index-time field extractions?

0 Karma

LukeMurphey
Champion

"TRANSFORMS-" is not the only indication of index-time knowledge. You also need to consider:

  • CHARSET
  • TRUNCATE
  • LINE_BREAKER
  • LINE_BREAKER_LOOKBEHIND
  • SHOULD_LINEMERGE
    • BREAK_ONLY_BEFORE_DATE
    • BREAK_ONLY_BEFORE
    • MUST_BREAK_AFTER
    • MUST_NOT_BREAK_AFTER
    • MUST_NOT_BREAK_BEFORE
    • MAX_EVENTS
  • DATETIME_CONFIG
  • TIME_PREFIX
  • MAX_TIMESTAMP_LOOKAHEAD
  • TIME_FORMAT
  • TZ
  • MAX_DAYS_AGO
  • MAX_DAYS_HENCE
  • MAX_DIFF_SECS_AGO
  • MAX_DIFF_SECS_HENCE
Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...