Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

Field Definitions Not Applied from Transforms.conf

$
0
0

I migrated my indexes to a new Splunk Server. I moved the transforms.conf and props.conf files to the new searcheads and the props.conf to the new indexers. This was the same set up that I used for the old Splunk servers. No changes have been made to the indexed data. I have a couple of sourcetypes that are in a CSV format and the field definitions are defined in the transforms.conf file.

When I run a search Splunk is not recognizing the field definitions. I validated that the transforms.conf file and the props.conf (in $splunk_home/etc/system/local) files have an acl of rwxrwxrwx. What could be wrong?


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>