I'm working with data that is being sent from a universal forwarder (UF) on the server. I do an INDEXED_EXTRACTION in the props.conf on the universal forwarder. When I search for the data on the search head (SH) it is put into the correct fields. I also have EVALs in the props.conf on the SH. What I don't see is the EVALs processed. This EVALS were processed in my standalone dev laptop, but not in the distributed environment. Do I need to move the EVALs to the UF?
↧