I have a Splunk 6.2.0 multisite cluster setup. Per site, there is one indexer, one search head and a master. I am pulling logs from a client on Windows using splunk universal forwarder, but I need to change the Line Break. I have defined a new sourcetype in props.conf and placed it on the client and restarted the splunkd on the client. I still don't see the changes when I search the data on the search head.
Do I have to define the sourcetype on the indexer as well? or just the indexer and not in the client?
Thanks
... View more