Splunk Search

Where to put extract statement

a212830
Champion

Hi,

I am processing some logs on a universal forwarder, which then sends the data to some indexers, which are searched from a search-head on a different server. I need to do an extract on the logfiles. Where should the extract statements go? In the props.conf on the receiving indexers, or the search-head?

Tags (2)
0 Karma

kristian_kolb
Ultra Champion

If you are talking about props.conf EXTRACT, or REPORT that should be on the search head.
If you are talking about index-time operations, like TRANSFORMS - on the indexer.

http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings

/K

0 Karma
Get Updates on the Splunk Community!

New Year, New Changes for Splunk Certifications

As we embrace a new year, we’re making a small but important update to the Splunk Certification ...

[Puzzles] Solve, Learn, Repeat: Unmerging HTML Tables

[Puzzles] Solve, Learn, Repeat: Unmerging HTML TablesFor a previous puzzle, I needed some sample data, and ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...