<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Transforms.conf not working as expected in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-isn-t-my-Transforms-conf-working-as-expected/m-p/638628#M109046</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251008"&gt;@DarshanBK&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;when you say ten rows are you meaning ten rows of each event or only ten events?&lt;/P&gt;&lt;P&gt;if the event's I'm not sure that's possible.&lt;/P&gt;&lt;P&gt;If you mean ten rows of each event, you can configurate the TRUNCATE parameter in props.conf to take only the first X chard of each event.&lt;/P&gt;&lt;P&gt;if one answer solves your need, please accept one answer for the other people of Community or tell me how I can help you.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
    <pubDate>Tue, 04 Apr 2023 10:30:55 GMT</pubDate>
    <dc:creator>gcusello</dc:creator>
    <dc:date>2023-04-04T10:30:55Z</dc:date>
    <item>
      <title>Why isn't my Transforms.conf working as expected?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-isn-t-my-Transforms-conf-working-as-expected/m-p/638541#M109032</link>
      <description>&lt;P&gt;I have below configurations in transforms and props config files to fetch only events containing keyword 'splunking' in the log files. But it seems to be not working .&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;transforms.conf&lt;/P&gt;
&lt;P&gt;[keepOnly10Lines]&lt;BR /&gt;REGEX=splunking&lt;BR /&gt;FORMAT=indexQueue&lt;BR /&gt;DEST_KEY=queue&lt;/P&gt;
&lt;P&gt;props.conf&lt;BR /&gt;[test-GP]&lt;BR /&gt;TRANSFORMS-set = keepOnly10Lines&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;inputs.conf&lt;/P&gt;
&lt;P&gt;[monitor:///opt/splunk/data/osheanTest/darsha_test*.log]&lt;BR /&gt;index = main&lt;BR /&gt;sourcetype = test-GP&lt;BR /&gt;disabled = 0&lt;BR /&gt;whitelist = .log$&lt;BR /&gt;move_policy = sinkhole&lt;BR /&gt;crcSalt = &amp;lt;source&amp;gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Below are the logs:&lt;/P&gt;
&lt;P&gt;05-12-2019 22:07:53.705 +0100 INFO splunkkkkkkkkkk - iueyrh8923f 2f82hob3f 208fhob 23f802ofb 2f8uo2bj f28ufb 2f892uobf2803fbuo j2f028bof j20fi oj&lt;BR /&gt;05-12-2019 22:07:53.705 +0100 INFO splunkingkkkkkkk - be27tf829fb 2u79fg2uibf 20fb 2f972gbu f20fb f0h2if 20f8bo f2hinfp 2fip 2f802fio2nf l&lt;BR /&gt;05-12-2019 22:07:53.705 +0100 INFO splunkkkkkkkkkk - uewhwf8iew cewuwbkj cobvjl ced08 jlwcuwojl vcew0vbjl wevcowejbl vwpeubvjl wvujwlevhwpivnwepviblj m&lt;BR /&gt;05-12-2019 22:07:53.705 +0100 INFO splunkkkkkkkkkk - 73ye9ubf 2fy92ou3bfj 2fhuo2bj f2yfdou2bj f208fhoub2jf02obfjl20fhinkf2pihbfl f9ip2knf c-92pjfpi2k 2-hpifn;k&lt;BR /&gt;05-12-2019 22:07:53.705 +0100 INFO splunkingkkkkkkk - ye08ru280fihn2 f20hfoib 2f0h2bi f2-9fpi2n f2fhpi2nk f2-9phifnk; 2fh2pibk f2fhpin;k&lt;BR /&gt;05-12-2019 22:07:53.705 +0100 INFO splunkkkkkkkkkk - ifhone 2n0ifnlk2 mfn082oihldj ovuce2h083do2bj fc028ifh3f8oih2lfdn2fob2jf80hi2pblj m9-2ufjpn;k f082hif 2&lt;BR /&gt;05-12-2019 22:07:53.705 +0100 INFO splunkingkkkkkkkkk - 8yd802hoifn 2fu2bj f28foub 2f9i2uk f2fobj 2fb 292fpin2 f29jpfin;k 2fpi2nf 0iphnfl 2fiplk 2fhipbl&lt;BR /&gt;05-12-2019 22:07:53.705 +0100 INFO splunkingkkkkkkk - d80dfh2inf280fyhoin2lf082hfoibnl 3df032u2inf2083yfh2n3f082y3fhn2 n2803f2ifn 2f820bf 280f2ob f280foi 2jl82u0ib&lt;BR /&gt;05-12-2019 22:07:53.705 +0100 INFO splunkkkkkkkkkk - e3ue832oin 23ifh23oilkf 2380ifb 23f802obuf 29-fhpi2 f290fpi 2f-2ipk&lt;BR /&gt;05-12-2019 22:07:53.705 +0100 INFO splunkingkkkkkkk - 3hd982yo802in f230f92hin3 f23fhpib2 3f230hpifn23fpi2b l&lt;BR /&gt;05-12-2019 22:07:53.705 +0100 INFO splunkingkkkkkkkkk - wyud8230foidn 2f02hiofn2fhpi2bf2hipfb2fpi2b3 f23f2-93fpi2n;k3 f2-fhpi2n3k; f2-39hpifnk; m&lt;BR /&gt;05-12-2019 22:07:53.705 +0100 INFO splunkkkkkkkkkk - feature="IOWait" color=green due_to_stanza="feature:iowait" node_type=feature node_path=splunkkkkkkkkkkd.resource_usage.iowait&lt;BR /&gt;05-12-2019 22:07:53.705 +0100 INFO splunkingkkkkkkkkk - vgavsgcavs chcyvashc msacyhasvc asasycvas casycvajs casyicxh darshan&lt;BR /&gt;05-12-2019 22:07:53.705 +0100 INFO splunkkkkkkkkkk - 10520523 3412 0520523 120523 120534gtey54y darshan&lt;BR /&gt;05-12-2019 21:37:53.702 +0100 INFO splunkkkkkkkkkk - 2052052ftrfquxutfxyiyqigx yhghck scxixb qcyicgkhqwmn cqwicykh darshan.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please help me in figuring out what is hindering splunk from applying transforms and props configuartions.&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 19:35:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-isn-t-my-Transforms-conf-working-as-expected/m-p/638541#M109032</guid>
      <dc:creator>DarshanBK</dc:creator>
      <dc:date>2023-04-04T19:35:44Z</dc:date>
    </item>
    <item>
      <title>Re: Transforms.conf not working as expected</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-isn-t-my-Transforms-conf-working-as-expected/m-p/638565#M109034</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251008"&gt;@DarshanBK&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;let me understand: you want to take all the events containing "&lt;SPAN&gt;splunking" and discard all the other events?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;if this is your requirement, your configuration isn't correct, as described at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/SplunkCloud/latest/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues" target="_blank"&gt;https://docs.splunk.com/Documentation/SplunkCloud/latest/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues&lt;/A&gt;&amp;nbsp;you have to configure two queues: one to take events and one to discard them.&lt;/P&gt;&lt;P&gt;something like this:&lt;/P&gt;&lt;P&gt;in props.conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[test-GP]
TRANSFORMS-set = keepOnly10Lines, setnull&lt;/LI-CODE&gt;&lt;P&gt;in transforms.conf&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[setnull]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue

[keepOnly10Lines]
REGEX=splunking
DEST_KEY = queue
FORMAT = indexQueue&lt;/LI-CODE&gt;&lt;P&gt;the order of commands (keepOnly10Lines before setnull) is relevant in props.conf, instead isn't relevant in transforms.conf the order of stanzas.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 06:45:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-isn-t-my-Transforms-conf-working-as-expected/m-p/638565#M109034</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-04-04T06:45:26Z</dc:date>
    </item>
    <item>
      <title>Re: Transforms.conf not working as expected</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-isn-t-my-Transforms-conf-working-as-expected/m-p/638590#M109040</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your suggestion!&lt;/P&gt;&lt;P&gt;I have one more requirement where we need to fetch only first 10lines from the above logs.&lt;/P&gt;&lt;P&gt;Its a huge file and consumes lot of license. so we need to index only first 10 lines.&lt;/P&gt;&lt;P&gt;Is it possible? if yes, how can we do it?&lt;/P&gt;&lt;P&gt;I have tried many option with no success.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can you please guide me ?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 08:35:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-isn-t-my-Transforms-conf-working-as-expected/m-p/638590#M109040</guid>
      <dc:creator>DarshanBK</dc:creator>
      <dc:date>2023-04-04T08:35:53Z</dc:date>
    </item>
    <item>
      <title>Re: Transforms.conf not working as expected</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-isn-t-my-Transforms-conf-working-as-expected/m-p/638628#M109046</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/251008"&gt;@DarshanBK&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;when you say ten rows are you meaning ten rows of each event or only ten events?&lt;/P&gt;&lt;P&gt;if the event's I'm not sure that's possible.&lt;/P&gt;&lt;P&gt;If you mean ten rows of each event, you can configurate the TRUNCATE parameter in props.conf to take only the first X chard of each event.&lt;/P&gt;&lt;P&gt;if one answer solves your need, please accept one answer for the other people of Community or tell me how I can help you.&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Tue, 04 Apr 2023 10:30:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-isn-t-my-Transforms-conf-working-as-expected/m-p/638628#M109046</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-04-04T10:30:55Z</dc:date>
    </item>
  </channel>
</rss>

