Has anyone ever used this app?
Seems to be really poorly documented although I get the fact that it is a search time transformation.
Can someone break it down for me on how to use this thing?
Also curious as to whether you can take these search time transforms and apply them at index time.
Let me know when you have a moment.
If I place this in the etc apps folder of a a universal forwarder I've intalled on a remote system, can I expect this to pull the data for the System Management section KB numbers under the Splunk supported Windows app?