Hello, small question about index time fields, if I want to create a new field with my logs coming from a syslog (eval function on my cribl), I have to put a fields.conf file on my splunk instance which declares all the new fields I will create from cribl ?example on fields.conf :[my_field]INDEXED=true[my_field2]INDEXED=trueIs this the only prerequisite for not having an error during indexing? As for the fields.conf, do you have to put it on the SH and IDX also in a distributed environment?
Question
New index time fields from a syslog
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
