Splunk Search

Why does a new field extraction not work on the search head just I created it on, but works immediately on other members in the search head cluster?

BP9906
Builder

Running the latest Splunk 6.2.2 with search head clustering. I found that when I create a new search field extraction, it doesnt immediately start to work on the current search head that I'm on. It will start working on the other cluster peers after replication grabs it (pretty quick).

Any idea why the current cluster peer wont start using it immediately?

0 Karma
1 Solution

BP9906
Builder

After some experimenting, I found that after completing the new field extraction, if I close out of what I was doing and go to a fresh search window (ie flashtimeline) then it would have the new extractions kick in. Odd.

View solution in original post

BP9906
Builder

After some experimenting, I found that after completing the new field extraction, if I close out of what I was doing and go to a fresh search window (ie flashtimeline) then it would have the new extractions kick in. Odd.

strangelaw
Explorer

Actually, I have similar kind of issue BUT my symptoms are worse 🙂

  • 2 Search Heads on Cluster
  • Made a Field extraction on node 1 (captain), sourcetype syslog:myown
  • Took while to show up, works on node 1 perfectly.
  • Node 2 - it replicates the field extraction, but never allows to use it/stays on list but does not invoke on search.

Anyone seen similar effect? I found no use for closing windows on neither head(s).

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...