So our current set up is the Splunk DBConnect is installed in one of our indexers. So i put my props and transforms in the indexer instance.
I'm trying to change the source field using the data from the query, So far I have successfully done this by copying one of the raw events from splunk then tried indexing it with the sourcetype that i configured.
But I when create an input in the dbconnect and applying that sourcetype, the source is not overriden.
the props/transforms work in my local when i upload the sample data below
TRANSFORMS-get_source = get_source
REGEX = SNPSHOT_DTTM="(?<capture1>\d+)-(?<capture2>\d+)-(?<capture3>\d+)\s(?<capture4>\d+):(?<capture5>\d+):\d+.\d",\smetric_period="(?<capture6>\w+)",\scurrent_or_prior="(?<capture7>\w+)"
DEST_KEY = MetaData:Source
FORMAT = source::coe_$6_$7_$1$2$3$4$5