Getting Data In

MetaData Values: Is there a difference between DEST_KEY = _MetaData:Index versus DEST_KEY = MetaData:Index?

Murali2888
Communicator

Is there any difference between the two below?

DEST_KEY = _MetaData:Index
DEST_KEY = MetaData:Index

Also, I would like to understand why the host, source, and sourcetype values are shown as MetaData:Host, whereas the index shows _MetaData:Index

Thanks for your help.

Regards
Murali

saurabh_tek11
Communicator

@Murali2888, DEST_KEY = MetaData:Index would be incorrect. Have a look on KEYS of transform.conf

Correct syntax as per splunk is _MetaData:Index, it defines the alternate index where the event shall be stored.

KEYs are case sensitive. NOTE: Any KEY (field name) prefixed by '_' is not indexed by Splunk, in general.

saurabh_tek11
Communicator

@Murali2888 hope this helps.

0 Karma

lguinn2
Legend

YES! There is a difference. Keys must be typed exactly as specified. The transform will not work otherwise.

I don't know why there is a difference between the keys that start with an underscore ( _ ) and those that do not. There is nothing in the documentation about that. My guess is that the difference is that the _ is used for metadata fields that are not stored in the journaled rawdata. Even if I am right, there is nothing that you or I can do about it, anyway; some keys start with _ and some don't!

Murali2888
Communicator

Thanks Iguinn for your comments.

There is no clear documentation available as to which keys need to be prefixed by ( _ ). I was hoping somebody would have some idea around this.

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to January Tech Talks, Office Hours, and Webinars!

What are Community Office Hours? Community Office Hours is an interactive 60-minute Zoom series where ...

[Puzzles] Solve, Learn, Repeat: Reprocessing XML into Fixed-Length Events

This challenge was first posted on Slack #puzzles channelFor a previous puzzle, I needed a set of fixed-length ...

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...