I'm a bit stuck with my issue.
I do have this splunk infra :
Sources ==> UF ==> Indexer cluster (3 + master) Search head cluster.
I'm trying to extract fields at index time to transform it in a future.
My props.conf and transfroms.conf are deployed in indexers throught the master.
log line look like :
WRITE_META = true
TRANSFORMS-csuser = fieldtestextract
TZ = utc
SEDCMD-username = s/,cs-user=\"[^\"]+\",/,cs-user="xxxx",/g
The SEDCMD is working like a charm but the tranforms won't work...
fields.conf on search heads :
INDEXED = true
INDEXED_VALUE = true
I don't see my field on search head and obsiously i'm not able to execute query against it.
Could you help me figuring out what's wrong with my configuration ?
Many thanks in advance.
I have found my mistake... my transforms file was named transform.conf (no S ...) It 's now working 🙂
@perezcla - thanks for posting your solution. We've moved your comment to an answer. Please accept your answer so that the question will show as closed. - dal