Splunk Search

Extraction Fails on Pooled Search Heads

tgiles
Path Finder

Hi,

Running into an issue in 4.2 (build 96430) where a field extraction works fine on an indexer, but the exact same extraction fails to run on pooled search heads.

after creating the extraction, I confirmed that the correct regex was listed under Fields > Field Extractions on both search heads.

Performed search and nothing returned. search inspector reports that "This search has completed, but did not match any events."

Forced the search to use the one index that I know there was relevant data, but still nothing returned.

We tested tags and event types without issue- they're both working as expected. Checked the props.conf on the pool and it's getting updated as expected.

Any thoughts on what might be causing the issue?

Thanks

0 Karma

tgiles
Path Finder

Was able to confirm this is a known issue with 4.2. An update will happen this week sometime to resolve it. Unfortunately, it's not documented on the knownissues for 4.2 quite yet.

0 Karma

tpsplunk
Communicator

did this ever get fixed?

0 Karma

tgiles
Path Finder

Quick note: also tried while logged in as admin user with same results. Thought perhaps it was a permissions issue- looks like that isn't the case.

0 Karma
Get Updates on the Splunk Community!

Splunk Classroom Chronicles: Training Tales and Testimonials (Episode 4)

Welcome back to Splunk Classroom Chronicles, our ongoing series where we shine a light on what really happens ...

From GPU to Application: Monitoring Cisco AI Infrastructure with Splunk Observability ...

AI workloads are different. They demand specialized infrastructure—powerful GPUs, enterprise-grade networking, ...

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...