Is there any difference between the two below?
DEST_KEY = _MetaData:Index
DEST_KEY = MetaData:Index
Also, I would like to understand why the host, source, and sourcetype values are shown as MetaData:Host, whereas the index shows _MetaData:Index
Thanks for your help.
Regards
Murali
@Murali2888, DEST_KEY = MetaData:Index would be incorrect. Have a look on KEYS of transform.conf
Correct syntax as per splunk is _MetaData:Index
, it defines the alternate index where the event shall be stored.
KEYs are case sensitive. NOTE: Any KEY (field name) prefixed by '_' is not indexed by Splunk, in general.
@Murali2888 hope this helps.
YES! There is a difference. Keys must be typed exactly as specified. The transform will not work otherwise.
I don't know why there is a difference between the keys that start with an underscore ( _
) and those that do not. There is nothing in the documentation about that. My guess is that the difference is that the _
is used for metadata fields that are not stored in the journaled rawdata. Even if I am right, there is nothing that you or I can do about it, anyway; some keys start with _
and some don't!
Thanks Iguinn for your comments.
There is no clear documentation available as to which keys need to be prefixed by ( _ ). I was hoping somebody would have some idea around this.