<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic What are the execution sequence of transforms from different stanza located in the difference configuration files ? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-execution-sequence-of-transforms-from-different/m-p/448812#M96436</link>
    <description>&lt;P&gt;We want to change sourcetype and then send data to two different Splunk Indexers.&lt;/P&gt;

&lt;P&gt;What is happening is the sourcetype is getting changed (that means first transform is working) BUT the seconds pros.conf stanza present in the apps folder is not working (It is only send the logs to default output group).&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Transform 1:&lt;/STRONG&gt; SPLUNK_HOME/etc/system/local/&lt;BR /&gt;
props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[source::/abc/xyz.log]
TRANSFORMS-changesourcetype = st
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[st]
REGEX = \.*\[12345]\.*
FORMAT = sourcetype::my_sourcetype
DEST_KEY = MetaData:Sourcetype
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Transform 2:&lt;/STRONG&gt; SPLUNK_HOME/etc/apps/application/local/&lt;BR /&gt;
props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[my_sourcetype]
TRANSFORMS-routing = route_data
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[route_data]
REGEX = .
DEST_KEY = _TCP_ROUTING
FORMAT = indexer1, indexer2
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Fri, 08 Feb 2019 02:47:26 GMT</pubDate>
    <dc:creator>fxyfrank_acn</dc:creator>
    <dc:date>2019-02-08T02:47:26Z</dc:date>
    <item>
      <title>What are the execution sequence of transforms from different stanza located in the difference configuration files ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-execution-sequence-of-transforms-from-different/m-p/448812#M96436</link>
      <description>&lt;P&gt;We want to change sourcetype and then send data to two different Splunk Indexers.&lt;/P&gt;

&lt;P&gt;What is happening is the sourcetype is getting changed (that means first transform is working) BUT the seconds pros.conf stanza present in the apps folder is not working (It is only send the logs to default output group).&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;Transform 1:&lt;/STRONG&gt; SPLUNK_HOME/etc/system/local/&lt;BR /&gt;
props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[source::/abc/xyz.log]
TRANSFORMS-changesourcetype = st
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[st]
REGEX = \.*\[12345]\.*
FORMAT = sourcetype::my_sourcetype
DEST_KEY = MetaData:Sourcetype
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;&lt;STRONG&gt;Transform 2:&lt;/STRONG&gt; SPLUNK_HOME/etc/apps/application/local/&lt;BR /&gt;
props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[my_sourcetype]
TRANSFORMS-routing = route_data
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[route_data]
REGEX = .
DEST_KEY = _TCP_ROUTING
FORMAT = indexer1, indexer2
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 08 Feb 2019 02:47:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-execution-sequence-of-transforms-from-different/m-p/448812#M96436</guid>
      <dc:creator>fxyfrank_acn</dc:creator>
      <dc:date>2019-02-08T02:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: What are the execution sequence of transforms from different stanza located in the difference configuration files ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-execution-sequence-of-transforms-from-different/m-p/448813#M96437</link>
      <description>&lt;P&gt;@fxyfrank_acn &lt;/P&gt;

&lt;P&gt;Please see &lt;STRONG&gt;How Splunk determines precedence order&lt;/STRONG&gt; and other section for your answer. &lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/Admin/Wheretofindtheconfigurationfiles"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.3/Admin/Wheretofindtheconfigurationfiles&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;You can run btool to see all the configuration values in use by your Splunk instance.&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Usebtooltotroubleshootconfigurations"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Usebtooltotroubleshootconfigurations&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 06:13:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-execution-sequence-of-transforms-from-different/m-p/448813#M96437</guid>
      <dc:creator>kamlesh_vaghela</dc:creator>
      <dc:date>2019-02-08T06:13:18Z</dc:date>
    </item>
    <item>
      <title>Re: What are the execution sequence of transforms from different stanza located in the difference configuration files ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-execution-sequence-of-transforms-from-different/m-p/448814#M96438</link>
      <description>&lt;P&gt;And there is the common misunderstanding: &lt;/P&gt;

&lt;P&gt;&lt;CODE&gt;btool&lt;/CODE&gt; does not show the actual config &lt;STRONG&gt;in use&lt;/STRONG&gt; by Splunk, it merges all on disk config files and shows the potential configuration Splunk is using ....&lt;/P&gt;

&lt;P&gt;Quote from the docs:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Btool displays merged on-disk configurations. That is, btool shows you the merged settings in the .conf files. It does not necessarily show you what Splunk software is currently using.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;link to the docs &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Usebtooltotroubleshootconfigurations"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Troubleshooting/Usebtooltotroubleshootconfigurations&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If you want to see the actual config Splunk is using right now, run this command:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;$SPLUNK_HOME/bin/splunk show config ....
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;links to the docs &lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Admin/CLIadmincommands"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Admin/CLIadmincommands&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;It is a bit like in the &lt;EM&gt;old&lt;/EM&gt; days with Cisco routers, there is a difference between &lt;CODE&gt;running config&lt;/CODE&gt; and &lt;CODE&gt;start-up config&lt;/CODE&gt; &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 06:21:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-execution-sequence-of-transforms-from-different/m-p/448814#M96438</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2019-02-08T06:21:04Z</dc:date>
    </item>
    <item>
      <title>Re: What are the execution sequence of transforms from different stanza located in the difference configuration files ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-execution-sequence-of-transforms-from-different/m-p/448815#M96439</link>
      <description>&lt;P&gt;Hello @fxyfrank_acn &lt;BR /&gt;
Can you please share the details present in &lt;CODE&gt;outputs.conf&lt;/CODE&gt; as well.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 07:20:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-execution-sequence-of-transforms-from-different/m-p/448815#M96439</guid>
      <dc:creator>vishaltaneja070</dc:creator>
      <dc:date>2019-02-08T07:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: What are the execution sequence of transforms from different stanza located in the difference configuration files ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-execution-sequence-of-transforms-from-different/m-p/448816#M96440</link>
      <description>&lt;P&gt;You have to mention something like this in &lt;CODE&gt;outputs.conf&lt;/CODE&gt; as well to make second transforms work:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tcpout:indexer1]
disabled=false
server=xx.x.xx.x:9997

[tcpout:indexer2]
disabled=false
server=xx.x.xx.x:9997
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 08 Feb 2019 07:22:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-execution-sequence-of-transforms-from-different/m-p/448816#M96440</guid>
      <dc:creator>vishaltaneja070</dc:creator>
      <dc:date>2019-02-08T07:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: What are the execution sequence of transforms from different stanza located in the difference configuration files ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-execution-sequence-of-transforms-from-different/m-p/448817#M96441</link>
      <description>&lt;P&gt;Have a look at my answer &lt;A href="https://answers.splunk.com/answers/686241/metadata-transforms-not-being-applied-after-series-1.html"&gt;https://answers.splunk.com/answers/686241/metadata-transforms-not-being-applied-after-series-1.html&lt;/A&gt; , you will get an idea what is happening.&lt;/P&gt;</description>
      <pubDate>Fri, 08 Feb 2019 09:08:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-execution-sequence-of-transforms-from-different/m-p/448817#M96441</guid>
      <dc:creator>harsmarvania57</dc:creator>
      <dc:date>2019-02-08T09:08:22Z</dc:date>
    </item>
    <item>
      <title>Re: What are the execution sequence of transforms from different stanza located in the difference configuration files ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-execution-sequence-of-transforms-from-different/m-p/448818#M96442</link>
      <description>&lt;P&gt;the two indexers are specified in the outputs.conf as what you have mentioned however it still doesn't work.&lt;/P&gt;

&lt;P&gt;I have tried to apply the Sourcetype change on the Indexer (indexing time), still no luck.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Feb 2019 03:43:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-execution-sequence-of-transforms-from-different/m-p/448818#M96442</guid>
      <dc:creator>fxyfrank_acn</dc:creator>
      <dc:date>2019-02-13T03:43:40Z</dc:date>
    </item>
    <item>
      <title>Re: What are the execution sequence of transforms from different stanza located in the difference configuration files ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-execution-sequence-of-transforms-from-different/m-p/526565#M96443</link>
      <description>&lt;P&gt;Since this will be performed at index parsing stage file precedence will be in global context so /system/local will have higher precedence than application/local.&amp;nbsp; So, in your case "my_sourcetype" will be created first then you can use "my_sourcetype" in application/local to redirect logs to different indexes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 02:46:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-execution-sequence-of-transforms-from-different/m-p/526565#M96443</guid>
      <dc:creator>anwarmian</dc:creator>
      <dc:date>2020-10-27T02:46:30Z</dc:date>
    </item>
  </channel>
</rss>

