Getting Data In

How can I force a transforms.conf to also run on data onboarded with collect?

sboogaar
Path Finder

I'm trying to make a test with data that I onboarded with the collect command.

What I see is that when I insert an event that is exactly the same as existing events, the data that I insert is not able to be searched on the fields while it is possible with the data that is normally onboarded.

My guess is that the transforms.conf configuration is not running on collect events, but I can not figure out how i can make sure it happens.

 

How can I force a transforms.conf to also run on data onboarded with collect?

Labels (2)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Are you using the _raw field to collect your events or are you setting fields?

Is your transforms based on sourcetype and are you setting sourcetype for the collect.

Note that the collect docs are not good and contain a number of errors.

You cannot pass a _time field - if you want _time, you have to put the time into a _raw field and let it be parsed there.

 

0 Karma
Get Updates on the Splunk Community!

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...

There's No Place Like Chrome and the Splunk Platform

WATCH NOW!Malware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

Customer Experience | Join the Customer Advisory Board!

Are you ready to take your Splunk journey to the next level? 🚀 We invite you to join our elite squad ...