Splunk Search

forwarding - where to define the field extraction : on sender or receiver?

imrago
Contributor

On splunkA I am monitoring an xml log file. It is forwarded to SplunkB in a separate index. Where should I define the multiline event breaking and the field extraction? On sender(splunkA) or receiver(splunkB)?

0 Karma
1 Solution

gkanapathy
Splunk Employee
Splunk Employee

Please see: http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F to learn how to determine where a configuration needs to reside.

View solution in original post

0 Karma

gkanapathy
Splunk Employee
Splunk Employee

Please see: http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F to learn how to determine where a configuration needs to reside.

0 Karma
Get Updates on the Splunk Community!

Get Schooled with Splunk Education: Explore Our Latest Courses

At Splunk Education, we’re dedicated to providing incredible learning experiences that cater to every skill ...

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL

Splunk AI Assistant for SPL | Key Use Cases to Unlock the Power of SPL  The Splunk AI Assistant for SPL ...

Buttercup Games: Further Dashboarding Techniques (Part 5)

This series of blogs assumes you have already completed the Splunk Enterprise Search Tutorial as it uses the ...