Deployment Architecture

Question about props.conf and light forwarders

responsys_cm
Builder

If I want to use SEDCMD to rewrite values in my data, should it be configured on the forwarder or the indexer?

Thx.

Craig

Tags (1)
0 Karma

jgedeon120
Contributor

If the forwarder is a heavy forwarder, full Splunk install, you can do it there. If not then you need to do it on the indexer.

responsys_cm
Builder

I'm running Splunk 4.3.4. I'm finding that I need to define my line breaking rules and timestamp extraction on the forwarder. Doing it on the indexer doesn't work.

0 Karma

jgedeon120
Contributor

I stand corrected, it can be done on a lightweight forwarder.

http://splunk-base.splunk.com/answers/45411/rewrite-_raw-from-universal-forwarder-not-working

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...