Splunk Search

Why is there a delay in applying field extraction updates?

phemmer
Path Finder

Whenever I update a field extraction, both from the search head UI field extraction helper, and via props.conf or transforms.conf, it always takes several minutes before the changes take effect.

  • Why?
  • Is there any way to speed it up?
  • Is there anything to monitor in the splunk logs (_internal index) to know when the update has taken effect so I don't have to just rerun the search over and over.

Some possibly relevant details:
Version 6.5.0
Search head clustering in use
props.conf/transforms.conf changes applied from a search head deployer node, and pushed via splunk apply shcluster-bundle.

jeremyhagand61
Communicator

I have this problem too

0 Karma

woodcock
Esteemed Legend

You can try a bump or a refresh but the latter will probably take longer than waiting:

http://docs.splunk.com/Documentation/Splunk/latest/AdvancedDev/CustomizationOptions

dd_msearles
Path Finder

Did you ever get to the bottom of this? I've always wondered about this and found it annoying.

0 Karma

snoobzilla
Builder

Don't know direct answer to your question. I do know that adding | extract reload=true to your searches will force reload at search time which is helpful if the problem statement is troubleshooting field extractions.

tb5821
Communicator

I downvoted this post because doesn't work

0 Karma

phemmer
Path Finder

Has no effect 😞

0 Karma

tb5821
Communicator

agree - doesn't seem to work.

0 Karma

snoobzilla
Builder

Are the extractions it has no effect on working eventually?

0 Karma

phemmer
Path Finder

Yes.

0 Karma

snoobzilla
Builder

😞

0 Karma
Get Updates on the Splunk Community!

Announcing Scheduled Export GA for Dashboard Studio

We're excited to announce the general availability of Scheduled Export for Dashboard Studio. Starting in ...

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics GA in US-AWS!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...