<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problems with props.conf and transforms.conf and similar hostnames in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40868#M9456</link>
    <description>&lt;P&gt;Are the both arriving via the same source?&lt;/P&gt;</description>
    <pubDate>Tue, 20 Nov 2012 20:48:07 GMT</pubDate>
    <dc:creator>Drainy</dc:creator>
    <dc:date>2012-11-20T20:48:07Z</dc:date>
    <item>
      <title>Problems with props.conf and transforms.conf and similar hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40863#M9451</link>
      <description>&lt;P&gt;I have 2 hostnames, let's call them "temp" and "temp001". Splunk is capturing "temp001" and placing it in the proper index, but it seems to be ignoring "temp". I think it is because "temp" is found within "temp001". How do I keep them separate and correct?&lt;/P&gt;

&lt;P&gt;I am uploading images of my props and transforms because the punctuation isn't showing up properly.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;props.conf&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://splunk-base.splunk.com//storage/props_1.gif" alt="Props.conf" /&gt;&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;transforms.conf&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://splunk-base.splunk.com//storage/transforms_2.gif" alt="transforms.conf" /&gt;&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2012 19:24:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40863#M9451</guid>
      <dc:creator>aferone</dc:creator>
      <dc:date>2012-11-20T19:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with props.conf and transforms.conf and similar hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40864#M9452</link>
      <description>&lt;P&gt;This might not be a regex issue. Try renaming the second props stanza as the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[host::temp001.domain1.domain2.com]
TRANSFORMS-idx_routing2 = temp001_idx_routing
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 20 Nov 2012 19:29:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40864#M9452</guid>
      <dc:creator>Rob</dc:creator>
      <dc:date>2012-11-20T19:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with props.conf and transforms.conf and similar hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40865#M9453</link>
      <description>&lt;P&gt;Thanks for the reply, but that didn't do anything.  I have 20 other stanzas that all have "TRANSFORMS-idx_routing=".  I did try it, but to no avail.&lt;/P&gt;

&lt;P&gt;Thanks again, though!&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2012 19:49:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40865#M9453</guid>
      <dc:creator>aferone</dc:creator>
      <dc:date>2012-11-20T19:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with props.conf and transforms.conf and similar hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40866#M9454</link>
      <description>&lt;P&gt;this might be a silly question but is it just a mistake where in props they are both .com and in transforms one is .gov?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2012 20:40:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40866#M9454</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-11-20T20:40:35Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with props.conf and transforms.conf and similar hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40867#M9455</link>
      <description>&lt;P&gt;Thanks for noticing!  &lt;/P&gt;

&lt;P&gt;No, that was a mistake in my editing for this post.  They are both the same ending.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2012 20:46:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40867#M9455</guid>
      <dc:creator>aferone</dc:creator>
      <dc:date>2012-11-20T20:46:58Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with props.conf and transforms.conf and similar hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40868#M9456</link>
      <description>&lt;P&gt;Are the both arriving via the same source?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2012 20:48:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40868#M9456</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-11-20T20:48:07Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with props.conf and transforms.conf and similar hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40869#M9457</link>
      <description>&lt;P&gt;Yes.  The whole reason I am doing these hosts this way is because it is coming from UDP:514, and these devices can't use an alternate port, which is how I normally direct my different sources to different indexes.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2012 20:50:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40869#M9457</guid>
      <dc:creator>aferone</dc:creator>
      <dc:date>2012-11-20T20:50:24Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with props.conf and transforms.conf and similar hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40870#M9458</link>
      <description>&lt;P&gt;how about if you just create the one stanza to rule them all? Using a regex like temp\d+.domain1.domain2.com?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2012 20:56:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40870#M9458</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-11-20T20:56:31Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with props.conf and transforms.conf and similar hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40871#M9459</link>
      <description>&lt;P&gt;I used a * and it didn't work.  You're saying to use +?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2012 20:57:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40871#M9459</guid>
      <dc:creator>aferone</dc:creator>
      <dc:date>2012-11-20T20:57:20Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with props.conf and transforms.conf and similar hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40872#M9460</link>
      <description>&lt;P&gt;Well this is a rex statement so you'll want to use something like \d+ which means match a number and the plus means keep consuming the characters until the number ends&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2012 20:59:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40872#M9460</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-11-20T20:59:04Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with props.conf and transforms.conf and similar hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40873#M9461</link>
      <description>&lt;P&gt;My RegEx is a little weak.  So if my 2 hostnames were ndgracs.dom1.dom2.com and ndgracs01.dom1.dom2.com, how would the RegEx look?&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2012 21:03:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40873#M9461</guid>
      <dc:creator>aferone</dc:creator>
      <dc:date>2012-11-20T21:03:57Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with props.conf and transforms.conf and similar hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40874#M9462</link>
      <description>&lt;P&gt;ndgracs\d+\.dom1\.dom2\.com should do the job, although it would need testing &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; I can't recall how exacting it is at index time, perhaps ndgracs(\d+\.|\.)dom1\.dom2\.com&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2012 21:08:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40874#M9462</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2012-11-20T21:08:57Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with props.conf and transforms.conf and similar hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40875#M9463</link>
      <description>&lt;P&gt;Well, I tried it, but I'm getting the same results.  It finds ndgracs01 and puts it in the right index, but ndgracs goes to the default.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2012 21:20:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40875#M9463</guid>
      <dc:creator>aferone</dc:creator>
      <dc:date>2012-11-20T21:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with props.conf and transforms.conf and similar hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40876#M9464</link>
      <description>&lt;P&gt;In props, I have both hosts stanzas going to the same stanza in transforms&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2012 21:21:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40876#M9464</guid>
      <dc:creator>aferone</dc:creator>
      <dc:date>2012-11-20T21:21:09Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with props.conf and transforms.conf and similar hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40877#M9465</link>
      <description>&lt;P&gt;In the case where there are no digits, you have to declare them as optional in your regex, maybe like this &lt;CODE&gt;ndgracs(\d+)?.dom1.dom2.com&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Nov 2012 21:56:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40877#M9465</guid>
      <dc:creator>sowings</dc:creator>
      <dc:date>2012-11-20T21:56:57Z</dc:date>
    </item>
    <item>
      <title>Re: Problems with props.conf and transforms.conf and similar hostnames</title>
      <link>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40878#M9466</link>
      <description>&lt;P&gt;Dang.  Still no dice.  It matches ndgracs01, but not ndgracs still.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Nov 2012 15:13:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/Problems-with-props-conf-and-transforms-conf-and-similar/m-p/40878#M9466</guid>
      <dc:creator>aferone</dc:creator>
      <dc:date>2012-11-21T15:13:07Z</dc:date>
    </item>
  </channel>
</rss>

