Getting Data In

Overwrites to multiple indexed fields possible in one transforms.conf stanza?

Runals
Motivator

We have some syslog feeds coming directly into an indexer. While this will eventually get addressed with forwarders I'd like to overwrite both the source and host indexed fields.
The forwarded syslogs looke like the following:

timestamp Forwarded from IP_address: whatever blah blah blah

and we are capturing the forwared from IP address in the following stanza

[forwarded]
DEST_KEY = MetaData:Host
REGEX = Forwarded\sfrom\s([^: ]+):
FORMAT = host::$1

Since I'd like to also grab the "whatever" and put it into the source field I'm wondering if I need to do that with a separate stanza in the transforms.conf file or if it can be included in the existing one. If it does require a second stanza in transforms can I call that from a second line in the props.conf stanza? For example

props.conf
[source blah]
TRANSFORMS-1=forwared
TRANSFORMS-2=forwared2

transforms.conf
[forwarded]
--as above--

[forwarded2]
DEST_KEY = MetaData:Source
REGEX = Forwarded\sfrom\s\d+\.\d+\.\d+\.\d+: (\S+)
FORMAT = source::$1

Have I overlooked anything?

Tags (1)
0 Karma
1 Solution

dwaddle
SplunkTrust
SplunkTrust

Because of needing to set DEST_KEY, I think your second approach with two different TRANSFORMS-xxx rules in props is the proper configuration.

View solution in original post

0 Karma

dwaddle
SplunkTrust
SplunkTrust

Because of needing to set DEST_KEY, I think your second approach with two different TRANSFORMS-xxx rules in props is the proper configuration.

0 Karma

Runals
Motivator

That was my thought/concern as well. Came into work this morning and added a second transforms call in the props and it did the trick. Thanks!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Cisco Data Fabric from Architecture to Investigation, Better SOC Visibility, and More ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

The Trust Gap: Why a Data Foundation is Fundamental to an Agentic Enterprise

The Trust Gap: Why a data foundation is fundamental to an  Agentic Enterprise.   Agentic AI is transforming ...

Data Management Digest – September 2026

    Welcome to the September 2026 edition of Data Management Digest! September brought a fresh wave of ...