Hi,
I have some access logs and want to use the provided out-of-the-box field extractions (access-extractions). I am using a custom named sourcetype. I've put the props and transforms on the indexer, but I'm still not seeing them. Do they need to go on the search-head?
Hi a212830,
check out this wiki http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings and have a closer look at the props.conf
in the parsing and the search section. Depending on your config it will either be the indexer or the search head.
hope this helps ...
cheers, MuS