Hello,
I'm creating an add-on that sets a data source and fields extractions.
First, I modify inputs.conf to set the UDP port. Then, using props.conf and tranforms.conf, I perform the field extractions. When I check on the web platform, (Manage -> Fields -> select the app) I can clearly see the list of fields. However, running the search none of the fields has been extracted.
Please note that I've restarted the splunk instance to apply changes, double checked the name of the config files. Plus, everything was working perfectly yesterday.
Please is there anyone who can help,
... View more