Getting Data In

How to set at the same time in transforms.conf a new index and set a new metadata  based on the host name?

FrankFZ
Engager

Hi, I need to set at the same time in transforms.conf a new index and set a new metadata  based on the host name.

New index=switchoob New metadata=tecnologia

Like this:
[force_IndexVMW]
SOURCE_KEY = MetaData:Host
REGEX = ^ob\w+
DEST_KEY = _MetaData:Index
FORMAT = switchoob

[force_tecnologiaVMW]
SOURCE_KEY = MetaData:Host
REGEX = ^ob\w+
DEST_KEY = _meta
FORMAT = NFV_SITE::DC02_MIBER tecnologia::vmw

I have tried to find "More than one DEST_KEY" article but the link is wrong.

Thank You

Labels (1)
0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

@FrankFZ - Please confirm the following things on your environment.

  • You have mentioned these two transforms stanzas in props.conf in the right source/sourcetype/host.
  • You have deployed this configuration at the parsing stage. Generally Indexer and Heavy Forwarder.
  • Make sure you are exporting this configuration to system level with local.meta or default.meta - https://docs.splunk.com/Documentation/Splunk/8.2.6/Admin/Defaultmetaconf 

 

You also need to add fields.conf on Search Head:

[tecnologia]
INDEXED=true

[NFV_SITE]
INDEXED=true

 

transforms.conf

[force_IndexVMW]
SOURCE_KEY = MetaData:Host
REGEX = ^ob\w+
DEST_KEY = _MetaData:Index
FORMAT = switchoob

[force_tecnologiaVMW]
SOURCE_KEY = MetaData:Host
REGEX = ^ob\w+
WRITE_META = true
FORMAT = NFV_SITE::DC02_MIBER tecnologia::vmw

 

I hope this helps!!! Upvote/Karma would be appreciated!!!

FrankFZ
Engager

Thanks very much for your suggestions. Do you confirm that the configuration of the transforms.conf file allows me to perform 2 redirections? One for the index and one for the meta field for the same hosts? Thank You!

0 Karma

VatsalJagani
SplunkTrust
SplunkTrust

Yes, that shouldn't be a problem.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Observability Simplified: Combining User Experience, Application Performance & ...

Tech Talk Observability Simplified: Combining User Experience, Application Performance & Network ...

Event Series May & June: From Network Visibility to Service Intelligence

Unifying the Network: Moving from Alert Noise to Service Intelligence with Splunk ITSI In today’s hybrid ...

Global Splunk User Group Events: May + June 2026

Your Splunk Community Awaits: Discover Upcoming User Group Events Worldwide    Staying ahead in the fast-paced ...