Splunk Search

Why does a new field extraction not work on the search head just I created it on, but works immediately on other members in the search head cluster?

BP9906
Builder

Running the latest Splunk 6.2.2 with search head clustering. I found that when I create a new search field extraction, it doesnt immediately start to work on the current search head that I'm on. It will start working on the other cluster peers after replication grabs it (pretty quick).

Any idea why the current cluster peer wont start using it immediately?

0 Karma
1 Solution

BP9906
Builder

After some experimenting, I found that after completing the new field extraction, if I close out of what I was doing and go to a fresh search window (ie flashtimeline) then it would have the new extractions kick in. Odd.

View solution in original post

BP9906
Builder

After some experimenting, I found that after completing the new field extraction, if I close out of what I was doing and go to a fresh search window (ie flashtimeline) then it would have the new extractions kick in. Odd.

strangelaw
Explorer

Actually, I have similar kind of issue BUT my symptoms are worse 🙂

  • 2 Search Heads on Cluster
  • Made a Field extraction on node 1 (captain), sourcetype syslog:myown
  • Took while to show up, works on node 1 perfectly.
  • Node 2 - it replicates the field extraction, but never allows to use it/stays on list but does not invoke on search.

Anyone seen similar effect? I found no use for closing windows on neither head(s).

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Community Content Calendar, September edition

Welcome to another insightful post from our Community Content Calendar! We're thrilled to continue bringing ...

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...