Hi,
I am processing some logs on a universal forwarder, which then sends the data to some indexers, which are searched from a search-head on a different server. I need to do an extract on the logfiles. Where should the extract statements go? In the props.conf on the receiving indexers, or the search-head?
If you are talking about props.conf EXTRACT, or REPORT that should be on the search head.
If you are talking about index-time operations, like TRANSFORMS - on the indexer.
http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings
/K