Splunk Search

Why does a new field extraction not work on the search head just I created it on, but works immediately on other members in the search head cluster?

BP9906
Builder

Running the latest Splunk 6.2.2 with search head clustering. I found that when I create a new search field extraction, it doesnt immediately start to work on the current search head that I'm on. It will start working on the other cluster peers after replication grabs it (pretty quick).

Any idea why the current cluster peer wont start using it immediately?

0 Karma
1 Solution

BP9906
Builder

After some experimenting, I found that after completing the new field extraction, if I close out of what I was doing and go to a fresh search window (ie flashtimeline) then it would have the new extractions kick in. Odd.

View solution in original post

BP9906
Builder

After some experimenting, I found that after completing the new field extraction, if I close out of what I was doing and go to a fresh search window (ie flashtimeline) then it would have the new extractions kick in. Odd.

strangelaw
Explorer

Actually, I have similar kind of issue BUT my symptoms are worse 🙂

  • 2 Search Heads on Cluster
  • Made a Field extraction on node 1 (captain), sourcetype syslog:myown
  • Took while to show up, works on node 1 perfectly.
  • Node 2 - it replicates the field extraction, but never allows to use it/stays on list but does not invoke on search.

Anyone seen similar effect? I found no use for closing windows on neither head(s).

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...