<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Is there a way to insert literal values into events before they are indexed? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-insert-literal-values-into-events-before-they/m-p/204329#M40331</link>
    <description>&lt;P&gt;If not happy with the answer, give us a scenario and details on how the inserts are valuable. There might be other ways to skin the cat than inserting literals.&lt;/P&gt;</description>
    <pubDate>Thu, 04 Aug 2016 14:07:51 GMT</pubDate>
    <dc:creator>sloshburch</dc:creator>
    <dc:date>2016-08-04T14:07:51Z</dc:date>
    <item>
      <title>Is there a way to insert literal values into events before they are indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-insert-literal-values-into-events-before-they/m-p/204327#M40329</link>
      <description>&lt;P&gt;Is there a way to insert values into events before they are indexed? We need to be able to insert string literals into our events before they are indexed. &lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2016 17:35:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-insert-literal-values-into-events-before-they/m-p/204327#M40329</guid>
      <dc:creator>erinboudreau</dc:creator>
      <dc:date>2016-08-03T17:35:51Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to insert literal values into events before they are indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-insert-literal-values-into-events-before-they/m-p/204328#M40330</link>
      <description>&lt;P&gt;Take a look at the REGEX and FORMAT attributes in the transforms.conf file.  See &lt;A href="http://docs.splunk.com/Documentation/Splunk/6.4.2/Admin/Transformsconf"&gt;http://docs.splunk.com/Documentation/Splunk/6.4.2/Admin/Transformsconf&lt;/A&gt;.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2016 17:53:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-insert-literal-values-into-events-before-they/m-p/204328#M40330</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2016-08-03T17:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to insert literal values into events before they are indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-insert-literal-values-into-events-before-they/m-p/204329#M40331</link>
      <description>&lt;P&gt;If not happy with the answer, give us a scenario and details on how the inserts are valuable. There might be other ways to skin the cat than inserting literals.&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2016 14:07:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-insert-literal-values-into-events-before-they/m-p/204329#M40331</guid>
      <dc:creator>sloshburch</dc:creator>
      <dc:date>2016-08-04T14:07:51Z</dc:date>
    </item>
  </channel>
</rss>

