Splunk Search

Do you have to use the props.conf method or GUI for a field extraction in a clustered environment?

joe06031990
Communicator

Hi,

For field extractions in a clustered environment do you have to use the props.conf method or can you use the field extractor GUI on the search head?

 

Thanks,

 

Joe

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

You can use either method.  The GUI will write changes to props.conf in the app's local directory, which the cluster will replicate to other members automatically.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

You can use either method.  The GUI will write changes to props.conf in the app's local directory, which the cluster will replicate to other members automatically.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

Fun with Regular Expression - multiples of nine

Fun with Regular Expression - multiples of nineThis challenge was first posted on Slack #regex channel ...

[Live Demo] Watch SOC transformation in action with the reimagined Splunk Enterprise ...

Overwhelmed SOC? Splunk ES Has Your Back Tool sprawl, alert fatigue, and endless context switching are making ...

What’s New & Next in Splunk SOAR

Security teams today are dealing with more alerts, more tools, and more pressure than ever.  Join us on ...