Splunk Search

Extraction Fails on Pooled Search Heads

tgiles
Path Finder

Hi,

Running into an issue in 4.2 (build 96430) where a field extraction works fine on an indexer, but the exact same extraction fails to run on pooled search heads.

after creating the extraction, I confirmed that the correct regex was listed under Fields > Field Extractions on both search heads.

Performed search and nothing returned. search inspector reports that "This search has completed, but did not match any events."

Forced the search to use the one index that I know there was relevant data, but still nothing returned.

We tested tags and event types without issue- they're both working as expected. Checked the props.conf on the pool and it's getting updated as expected.

Any thoughts on what might be causing the issue?

Thanks

0 Karma

tgiles
Path Finder

Was able to confirm this is a known issue with 4.2. An update will happen this week sometime to resolve it. Unfortunately, it's not documented on the knownissues for 4.2 quite yet.

0 Karma

tpsplunk
Communicator

did this ever get fixed?

0 Karma

tgiles
Path Finder

Quick note: also tried while logged in as admin user with same results. Thought perhaps it was a permissions issue- looks like that isn't the case.

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...