Splunk Search

Why is there a delay in applying field extraction updates?

phemmer
Path Finder

Whenever I update a field extraction, both from the search head UI field extraction helper, and via props.conf or transforms.conf, it always takes several minutes before the changes take effect.

  • Why?
  • Is there any way to speed it up?
  • Is there anything to monitor in the splunk logs (_internal index) to know when the update has taken effect so I don't have to just rerun the search over and over.

Some possibly relevant details:
Version 6.5.0
Search head clustering in use
props.conf/transforms.conf changes applied from a search head deployer node, and pushed via splunk apply shcluster-bundle.

jeremyhagand61
Communicator

I have this problem too

0 Karma

woodcock
Esteemed Legend

You can try a bump or a refresh but the latter will probably take longer than waiting:

http://docs.splunk.com/Documentation/Splunk/latest/AdvancedDev/CustomizationOptions

dd_msearles
Path Finder

Did you ever get to the bottom of this? I've always wondered about this and found it annoying.

0 Karma

snoobzilla
Builder

Don't know direct answer to your question. I do know that adding | extract reload=true to your searches will force reload at search time which is helpful if the problem statement is troubleshooting field extractions.

tb5821
Communicator

I downvoted this post because doesn't work

0 Karma

phemmer
Path Finder

Has no effect 😞

0 Karma

tb5821
Communicator

agree - doesn't seem to work.

0 Karma

snoobzilla
Builder

Are the extractions it has no effect on working eventually?

0 Karma

phemmer
Path Finder

Yes.

0 Karma

snoobzilla
Builder

😞

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...