Splunk Search

Why is there a delay in applying field extraction updates?

phemmer
Path Finder

Whenever I update a field extraction, both from the search head UI field extraction helper, and via props.conf or transforms.conf, it always takes several minutes before the changes take effect.

  • Why?
  • Is there any way to speed it up?
  • Is there anything to monitor in the splunk logs (_internal index) to know when the update has taken effect so I don't have to just rerun the search over and over.

Some possibly relevant details:
Version 6.5.0
Search head clustering in use
props.conf/transforms.conf changes applied from a search head deployer node, and pushed via splunk apply shcluster-bundle.

jeremyhagand61
Communicator

I have this problem too

0 Karma

woodcock
Esteemed Legend

You can try a bump or a refresh but the latter will probably take longer than waiting:

http://docs.splunk.com/Documentation/Splunk/latest/AdvancedDev/CustomizationOptions

dd_msearles
Path Finder

Did you ever get to the bottom of this? I've always wondered about this and found it annoying.

0 Karma

snoobzilla
Builder

Don't know direct answer to your question. I do know that adding | extract reload=true to your searches will force reload at search time which is helpful if the problem statement is troubleshooting field extractions.

tb5821
Communicator

I downvoted this post because doesn't work

0 Karma

phemmer
Path Finder

Has no effect 😞

0 Karma

tb5821
Communicator

agree - doesn't seem to work.

0 Karma

snoobzilla
Builder

Are the extractions it has no effect on working eventually?

0 Karma

phemmer
Path Finder

Yes.

0 Karma

snoobzilla
Builder

😞

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...