Getting Data In

Log to Metrics - No data preview displayed when Metric Measures names are present

ashmaind
Explorer

I am trying Log to metric conversion feature. I tried getting data in using Add Data feature. But no data preview gets displayed when the sourcetype is selected for log to metric conversion. While playing around I observed that data preview is getting displayed when METRIC-SCHEMA-TRANSFORMS Advanced setting is removed.
Here is my stanza for the sourcetype I created

[log_to_met]
DATETIME_CONFIG =
INDEXED_EXTRACTIONS = csv
LINE_BREAKER = ([\r\n]+)
METRIC-SCHEMA-TRANSFORMS = metric-schema:log_to_met_1546498662303
NO_BINARY_CHECK = true
category = Log to Metrics
pulldown_type = 1
disabled = false

transforms.conf stanza
[metric-schema:log_to_met_1546498662303]
METRIC-SCHEMA-MEASURES = _value

So, what are these Metric Measures and how to get data in with these measures. Also what is the importance of log to metric conversion.

0 Karma
Get Updates on the Splunk Community!

Technical Workshop Series: Splunk Data Management and SPL2 | Register here!

Hey, Splunk Community! Ready to take your data management skills to the next level? Join us for a 3-part ...

Spotting Financial Fraud in the Haystack: A Guide to Behavioral Analytics with Splunk

In today's digital financial ecosystem, security teams face an unprecedented challenge. The sheer volume of ...

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability

Solve Problems Faster with New, Smarter AI and Integrations in Splunk Observability As businesses scale ...