Splunk Search

Issues with props and transforms

Abha11
Explorer

Hi All,

I have just copied across working props and transforms stanza from one HF to another for sqs logs. 

however it’s having issues on using this props and transforms since logs are stopping and I am getting a message “start writing events to STDOUT” host=“ “ index=“<index>main</index>” stanza= “ “

 

I am using that transforms to extract hostname index name , source and sourcetype. 

any help appreciated! Thanks 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you restart that HF after you have installed those copies to it?

You could use splunk btool props list <sourcetype name> and splunk btool transforms list <transform name> to see that splunk found those correctly. If needed add --debug to see where it takes those into use.

r. Ismo

0 Karma

Abha11
Explorer

Hi @isoutamo 

@Thank you so much for your reply to my question. 

so I had restarted HF after applying the props and transforms, but no luck. I also checked via btool that props and transforms  were found by Splunk correctly, with the debug I could see they were sitting in my splunk add on for aws. 

I tried not to use this props and transforms and created and used another sourcetype and I could see my data came in. 

however I need to use transforms to set host source and sourcetype based on event data. 
samd props and transforms working on another HF I copied it from. Not sure what is going wrong here since on using these splunk starts to write events to STDOUT.

 

any help appreciated!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...

Upgrade Prep for 10.4, Network Observability Deep Dives, and More from Splunk Lantern

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Splunk Developer Day announcements: AI agents, MCP tools, Forecasting, and Custom ...

Splunk Developer Day was packed with product and platform updates for developers building in the AI ...