Hi All,
I am trying to integrate a csv file in Splunk. I have created a cluter with one Search head, two indexers. For field extraction i need to edit the props.conf and transforms.conf at both indexers through masters (pushing through masters at both peers) or i need to manually paste both configuration files at indexers ?
regards,
Sourabh
Search peer / slave configuration needs to be pushed through from the master.
That sounds like something went wrong. Check Splunk logs, your configuration, etc. - make sure you're following the docs, such as this: http://docs.splunk.com/Documentation/Splunk/latest/Indexer/Updatepeerconfigurations
Pushing the bundle from the master to the peers is the only supported method of distributing peer configurations.
But when i am trying to push the configuration files from master to peers, the default and local folders under $SPLUNK_HOME$etcslave-apps_cluster on peers got deleted and cluster stopped working. Is their any work around ?