I m using app - OKTA identity cloud deployed on Indexer has built -in sourcetype OktaIM2:log - field extractions . I am seeing those fields when I am running query on Indexer . But the same query when run on Search head , I am seeing less field extractions - specially the ones in advanced section . Attached is the screenshot of the advanced setting of sourcetype.
Why is this happening ? I have not faced this issue before ?
@rashi83 - In the distributed environment, you need to deploy this app on Search head as well along with the Heavy forwarder. May be this documentation will help https://raw.githubusercontent.com/mbegan/Okta-Identity-Cloud-for-Splunk/master/README/Okta%20Identit...