Getting Data In

Help with setting index and sourcetype via transforms.conf

Champion

Hi,

I want to override the "unknown" index that some of my syslog messages are coming in as, using props and transforms. The index part is working, but the sourcetype is not setting. Not sure what I'm doing wrong... if someone can take a look, I'd appreciate it.

props.conf:
[unknown]
KV_MODE=auto
ANNOTATE_PUNCT=false
MAX_TIMESTAMP_LOOKAHEAD = 50
TRANSFORMS-set = ciscoIOS_index_parser,ciscoIOS_sourcetype_parser

transforms.conf:

[ciscoIOS_index_parser]
REGEX = %[A-Z_]+-[0-9]-[A-Z_]+:
DEST_KEY = _MetaData:Index
FORMAT = cisco

[ciscoIOS_sourcetype_parser]
REGEX = %[A-Z_]+-[0-9]-[A-Z_]+:
DEST_KEY = _MetaData:Sourcetype
FORMAT = sourcetype::cisco:ios
0 Karma

Ultra Champion
0 Karma

Ultra Champion

Should be DEST_KEY = MetaData:Sourcetype without the _.

See also: http://docs.splunk.com/Documentation/Splunk/latest/Admin/Transformsconf#KEYS:

Don’t Miss Global Splunk
User Groups Week!

Free LIVE events worldwide 2/8-2/12
Connect, learn, and collect rad prizes and swag!