Good morning,
I have a question regarding Office 365 data:
Is there a way to write a transforms.conf or props.conf with which I could parse the data with certain domains to go to one index and data with certain domains to the other?
Thank you,
Oliver
Hi omuelle1,
yiou have to write a props.conf and transforma.conf on your indexers; if you have an Heavy Forwarders (and you should have it) you have to put these files on the Heavy Forwarders.
On props.conf
[mysourcetype]
TRANSFORMS-index = overrideindex
On transforms.conf
[overrideindex]
DEST_KEY =_MetaData:Index
REGEX = my_regex
FORMAT = my_new_index
where my_regex is the regex that identifies the logs to forward to a different Index.
Bye.
Giuseppe
Hi omuelle1,
yiou have to write a props.conf and transforma.conf on your indexers; if you have an Heavy Forwarders (and you should have it) you have to put these files on the Heavy Forwarders.
On props.conf
[mysourcetype]
TRANSFORMS-index = overrideindex
On transforms.conf
[overrideindex]
DEST_KEY =_MetaData:Index
REGEX = my_regex
FORMAT = my_new_index
where my_regex is the regex that identifies the logs to forward to a different Index.
Bye.
Giuseppe
Thank you I just did that with some test data and it worked. I will need to try it as well once I have the live data.
Hi omuelle1,
if you're satisfied by this answer, please accept and/ot upvote it.
We'll see for the next tip.
Bye.
Giuseppe
What in the actual events or data tells them apart? What about the file name? Could you provide a data sample and highlight what differentiates them?