Splunk Search

Extraction Fails on Pooled Search Heads

tgiles
Path Finder

Hi,

Running into an issue in 4.2 (build 96430) where a field extraction works fine on an indexer, but the exact same extraction fails to run on pooled search heads.

after creating the extraction, I confirmed that the correct regex was listed under Fields > Field Extractions on both search heads.

Performed search and nothing returned. search inspector reports that "This search has completed, but did not match any events."

Forced the search to use the one index that I know there was relevant data, but still nothing returned.

We tested tags and event types without issue- they're both working as expected. Checked the props.conf on the pool and it's getting updated as expected.

Any thoughts on what might be causing the issue?

Thanks

0 Karma

tgiles
Path Finder

Was able to confirm this is a known issue with 4.2. An update will happen this week sometime to resolve it. Unfortunately, it's not documented on the knownissues for 4.2 quite yet.

0 Karma

tpsplunk
Communicator

did this ever get fixed?

0 Karma

tgiles
Path Finder

Quick note: also tried while logged in as admin user with same results. Thought perhaps it was a permissions issue- looks like that isn't the case.

0 Karma
Get Updates on the Splunk Community!

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...

AI for AppInspect

We’re excited to announce two new updates to AppInspect designed to save you time and make the app approval ...

App Platform's 2025 Year in Review: A Year of Innovation, Growth, and Community

As we step into 2026, it’s the perfect moment to reflect on what an extraordinary year 2025 was for the Splunk ...