Getting Data In

How can I force a transforms.conf to also run on data onboarded with collect?

sboogaar
Path Finder

I'm trying to make a test with data that I onboarded with the collect command.

What I see is that when I insert an event that is exactly the same as existing events, the data that I insert is not able to be searched on the fields while it is possible with the data that is normally onboarded.

My guess is that the transforms.conf configuration is not running on collect events, but I can not figure out how i can make sure it happens.

 

How can I force a transforms.conf to also run on data onboarded with collect?

Labels (2)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Are you using the _raw field to collect your events or are you setting fields?

Is your transforms based on sourcetype and are you setting sourcetype for the collect.

Note that the collect docs are not good and contain a number of errors.

You cannot pass a _time field - if you want _time, you have to put the time into a _raw field and let it be parsed there.

 

0 Karma
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...