Splunk Search

Extraction Fails on Pooled Search Heads

tgiles
Path Finder

Hi,

Running into an issue in 4.2 (build 96430) where a field extraction works fine on an indexer, but the exact same extraction fails to run on pooled search heads.

after creating the extraction, I confirmed that the correct regex was listed under Fields > Field Extractions on both search heads.

Performed search and nothing returned. search inspector reports that "This search has completed, but did not match any events."

Forced the search to use the one index that I know there was relevant data, but still nothing returned.

We tested tags and event types without issue- they're both working as expected. Checked the props.conf on the pool and it's getting updated as expected.

Any thoughts on what might be causing the issue?

Thanks

0 Karma

tgiles
Path Finder

Was able to confirm this is a known issue with 4.2. An update will happen this week sometime to resolve it. Unfortunately, it's not documented on the knownissues for 4.2 quite yet.

0 Karma

tpsplunk
Communicator

did this ever get fixed?

0 Karma

tgiles
Path Finder

Quick note: also tried while logged in as admin user with same results. Thought perhaps it was a permissions issue- looks like that isn't the case.

0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...