Getting Data In

Where do Report extractions go

a212830
Champion

Hi,

I have some access logs and want to use the provided out-of-the-box field extractions (access-extractions). I am using a custom named sourcetype. I've put the props and transforms on the indexer, but I'm still not seeing them. Do they need to go on the search-head?

0 Karma

MuS
Legend

Hi a212830,

check out this wiki http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings and have a closer look at the props.conf in the parsing and the search section. Depending on your config it will either be the indexer or the search head.

hope this helps ...

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to May Tech Talks, Office Hours, and Webinars!

Take a look below to explore our upcoming Community Office Hours, Tech Talks, and Webinars this month. This ...

They're back! Join the SplunkTrust and MVP at .conf24

With our highly anticipated annual conference, .conf, comes the fez-wearers you can trust! The SplunkTrust, as ...

Enterprise Security Content Update (ESCU) | New Releases

Last month, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...