Splunk Search

Extraction Fails on Pooled Search Heads

tgiles
Path Finder

Hi,

Running into an issue in 4.2 (build 96430) where a field extraction works fine on an indexer, but the exact same extraction fails to run on pooled search heads.

after creating the extraction, I confirmed that the correct regex was listed under Fields > Field Extractions on both search heads.

Performed search and nothing returned. search inspector reports that "This search has completed, but did not match any events."

Forced the search to use the one index that I know there was relevant data, but still nothing returned.

We tested tags and event types without issue- they're both working as expected. Checked the props.conf on the pool and it's getting updated as expected.

Any thoughts on what might be causing the issue?

Thanks

0 Karma

tgiles
Path Finder

Was able to confirm this is a known issue with 4.2. An update will happen this week sometime to resolve it. Unfortunately, it's not documented on the knownissues for 4.2 quite yet.

0 Karma

tpsplunk
Communicator

did this ever get fixed?

0 Karma

tgiles
Path Finder

Quick note: also tried while logged in as admin user with same results. Thought perhaps it was a permissions issue- looks like that isn't the case.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...