Splunk Search

Where to put extract statement

a212830
Champion

Hi,

I am processing some logs on a universal forwarder, which then sends the data to some indexers, which are searched from a search-head on a different server. I need to do an extract on the logfiles. Where should the extract statements go? In the props.conf on the receiving indexers, or the search-head?

Tags (2)
0 Karma

kristian_kolb
Ultra Champion

If you are talking about props.conf EXTRACT, or REPORT that should be on the search head.
If you are talking about index-time operations, like TRANSFORMS - on the indexer.

http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings

/K

0 Karma
Get Updates on the Splunk Community!

Community Content Calendar, November Edition

Welcome to the November edition of our Community Spotlight! Each month, we dive into the Splunk Community to ...

October Community Champions: A Shoutout to Our Contributors!

As October comes to a close, we want to take a moment to celebrate the people who make the Splunk Community ...

Stay Connected: Your Guide to November Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...