Hello All
My current environment is as follows :
Syslog/UF (Universal Forwarder) -> HF (Heavy Forwarder) -> Indexers
I am trying to perform an indexed time fieldextraction so that p...
I need help indexing CSV files.
I have read this, http://docs.splunk.com/Documentation/Splunk/6.2.1/Admin/Propsconf
My props.conf
[test_csv]
INDEXED_EXTRACTIONS = CSV
FIELD...
Hi,
I've recently noticed the recommendations the move to search-time versus index-time fieldextractions. I'm trying to get an idea of exactly how much of the configuration that we've got in p...
We use a custom format for our Apache access logs. Long ago, I put together a regex to extract the fields from the custom format. At that time, I set it up as a fieldextraction on the indexer....
We are trying to index a psv file into Splunk with sourcetype as "psv", but its not extracting fields from the PSV's first row. Can you please provide the config to add fields as psv header/first r...
...dd_app_env
[add_env_field]
TRANSFORMS-env = add_app_env
fields.conf
[add_app_env]
INDEXED=true
But I do not get my app and env fields and I have no idea how to debug this other than trial and e...
I'm using indexedfieldextraction to ingest JSON data over the HTTP Event Collector.
It works great. Except, once the event is > 10k bytes, the fields within the JSON are not indexed a...
Does anyone have troubleshooting steps on how to troubleshoot parse time or index time related issue. The use case sourcetype override or sending thing to nullQueue and filter.
The reason f...
Hello, I am using an extractfield at search time called "src_ip". To optimize search response times, I have create an indexedfieldextraction called "src_ip-index". How to "backendly" configure...
...s not having the issues below.
For some reason it is not picking up any new search time extractions or fieldaliases from either props or transforms. I've made sure the permissions were global. I...