Getting Data In

How can I force a transforms.conf to also run on data onboarded with collect?

sboogaar
Path Finder

I'm trying to make a test with data that I onboarded with the collect command.

What I see is that when I insert an event that is exactly the same as existing events, the data that I insert is not able to be searched on the fields while it is possible with the data that is normally onboarded.

My guess is that the transforms.conf configuration is not running on collect events, but I can not figure out how i can make sure it happens.

 

How can I force a transforms.conf to also run on data onboarded with collect?

Labels (2)
0 Karma

bowesmana
SplunkTrust
SplunkTrust

Are you using the _raw field to collect your events or are you setting fields?

Is your transforms based on sourcetype and are you setting sourcetype for the collect.

Note that the collect docs are not good and contain a number of errors.

You cannot pass a _time field - if you want _time, you have to put the time into a _raw field and let it be parsed there.

 

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Thanks for the Memories: .conf26 Took Learning to New Heights

Thank you, Splunk Community, for making .conf26 in Denver one for the books. From packed Splunk University ...

Best Practices: Splunk auto adjust pipeline queue

When you enable autoAdjustQueue in Splunk, maxSize should be understood as the queue size Splunk starts with ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...