Getting Data In

Clone an event based on a indexed field

duijva1
Engager

Hi all,

We have a source which comes in via HEC into an index.

The sourcetyping currently is dynamic.
We then route data based on a indexed label the data to a specific index.

Here comes the catch.

If we have another indexed field called label we want to clone that event into a new index and sourcetype

 

props.conf

 

 

[(?::){0}kube:container:*] 
TRANSFORMS-route_by_domain_label = route_by_domain_label

 

 

 

transforms.conf

We route the data based on a label which is custom named k8s_label for the example here

and for sensitive data we also have a label called : label_sensitive 

 

 

[route_index_by_label_domain]
SOURCE_KEY = field:k8s_label
REGEX = index_domain_(\w+)
FORMAT = indexname_$1
DEST_KEY = _MetaData:Index

[clone_when_sensitive]
SOURCE_KEY = field:label_sensitive
REGEX = true
DEST_KEY = _MetaData:Sourcetype
#CLONE_SOURCETYPE = sensitive_events
FORMAT = sourcetype::sensitive_events

 

 

Labels (1)
Tags (1)
0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...