Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Where do I put props.conf and transforms.conf stanzas to parse custom IIS and firewall fields? Will this impact previously indexed data?

$
0
0
I am trying to parse custom IIS and Windows Firewall fields using props and transforms. Our Universal Forwarders first send logs to Heavy Forwarders, then to the Indexers. Where is the proper place to put the props and transforms so that the fields are parsed correctly? Also, will this affect data already indexed, or just new data? Thanks. This has always been confusing to me, so thanks for helping!

Viewing all articles
Browse latest Browse all 47296


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>