Getting Data In

How to set at the same time in transforms.conf a new index and set a new metadata  based on the host name?

FrankFZ
Engager

Hi, I need to set at the same time in transforms.conf a new index and set a new metadata  based on the host name.

New index=switchoob New metadata=tecnologia

Like this:
[force_IndexVMW]
SOURCE_KEY = MetaData:Host
REGEX = ^ob\w+
DEST_KEY = _MetaData:Index
FORMAT = switchoob

[force_tecnologiaVMW]
SOURCE_KEY = MetaData:Host
REGEX = ^ob\w+
DEST_KEY = _meta
FORMAT = NFV_SITE::DC02_MIBER tecnologia::vmw

I have tried to find "More than one DEST_KEY" article but the link is wrong.

Thank You

Labels (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@FrankFZ - Please confirm the following things on your environment.

  • You have mentioned these two transforms stanzas in props.conf in the right source/sourcetype/host.
  • You have deployed this configuration at the parsing stage. Generally Indexer and Heavy Forwarder.
  • Make sure you are exporting this configuration to system level with local.meta or default.meta - https://docs.splunk.com/Documentation/Splunk/8.2.6/Admin/Defaultmetaconf 

 

You also need to add fields.conf on Search Head:

[tecnologia]
INDEXED=true

[NFV_SITE]
INDEXED=true

 

transforms.conf

[force_IndexVMW]
SOURCE_KEY = MetaData:Host
REGEX = ^ob\w+
DEST_KEY = _MetaData:Index
FORMAT = switchoob

[force_tecnologiaVMW]
SOURCE_KEY = MetaData:Host
REGEX = ^ob\w+
WRITE_META = true
FORMAT = NFV_SITE::DC02_MIBER tecnologia::vmw

 

I hope this helps!!! Upvote/Karma would be appreciated!!!

FrankFZ
Engager

Thanks very much for your suggestions. Do you confirm that the configuration of the transforms.conf file allows me to perform 2 redirections? One for the index and one for the meta field for the same hosts? Thank You!

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Yes, that shouldn't be a problem.

Get Updates on the Splunk Community!

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...

Splunk MCP & Agentic AI: Machine Data Without Limits

Discover how the Splunk Model Context Protocol (MCP) Server can revolutionize the way your organization uses ...