Splunk Search

Issues with props and transforms

Abha11
Explorer

Hi All,

I have just copied across working props and transforms stanza from one HF to another for sqs logs. 

however it’s having issues on using this props and transforms since logs are stopping and I am getting a message “start writing events to STDOUT” host=“ “ index=“<index>main</index>” stanza= “ “

 

I am using that transforms to extract hostname index name , source and sourcetype. 

any help appreciated! Thanks 

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Have you restart that HF after you have installed those copies to it?

You could use splunk btool props list <sourcetype name> and splunk btool transforms list <transform name> to see that splunk found those correctly. If needed add --debug to see where it takes those into use.

r. Ismo

0 Karma

Abha11
Explorer

Hi @isoutamo 

@Thank you so much for your reply to my question. 

so I had restarted HF after applying the props and transforms, but no luck. I also checked via btool that props and transforms  were found by Splunk correctly, with the debug I could see they were sitting in my splunk add on for aws. 

I tried not to use this props and transforms and created and used another sourcetype and I could see my data came in. 

however I need to use transforms to set host source and sourcetype based on event data. 
samd props and transforms working on another HF I copied it from. Not sure what is going wrong here since on using these splunk starts to write events to STDOUT.

 

any help appreciated!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...