In the diagrammed environment shown below, the customer would like the data read by the universal forwarders to set an indexed field containing the UF's host name. Where would the parsing configurations need to be installed for this to work?
the key here is "parsing" instances. the hosts sending directly requires parsing on the indexer peers and the hosts sending to the HFs require parsing on the HF instances. so all parsing instances is the right answer
D, the props and transforms will go on the HF if there is one(which in this case there is) and then the IDXs will need a fields.conf.
https://docs.splunk.com/Documentation/Splunk/9.0.2/Data/Configureindex-timefieldextraction
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
hpbdcb
11 months agocornripper
2 years agoRedtonyeah
2 years, 7 months ago