Splunk Enterprise

Field extractions not getting replicated on Search head

rashi83
Path Finder

Hi,

I m using app - OKTA identity cloud deployed on Indexer has built -in sourcetype OktaIM2:log - field extractions . I am seeing those fields when I am running query on Indexer . But the same query when run on Search head , I am seeing less field extractions - specially the ones in advanced section . Attached is the screenshot of the advanced setting of sourcetype.

Why is this happening ? I have not faced this issue before ?

Tags (1)
0 Karma

Vijeta
Influencer

@rashi83 - In the distributed environment, you need to deploy this app on Search head as well along with the Heavy forwarder. May be this documentation will help https://raw.githubusercontent.com/mbegan/Okta-Identity-Cloud-for-Splunk/master/README/Okta%20Identit...

0 Karma

to4kawa
Ultra Champion

Is there same props.conf and transforms.conf?

0 Karma

rashi83
Path Finder

@to4kawa : There is props and transforms in default folder . What is the question - is it same ? NO.

0 Karma
Get Updates on the Splunk Community!

Index This | I am a number, but when you add ‘G’ to me, I go away. What number am I?

March 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...

What’s New in Splunk App for PCI Compliance 5.3.1?

The Splunk App for PCI Compliance allows customers to extend the power of their existing Splunk solution with ...

Extending Observability Content to Splunk Cloud

Register to join us !   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to ...