Getting Data In

Problems with setting sourcetype through transformations.conf

quixand
Path Finder

This is driving me mad - have gone through the documentation and responses to queries in here but still can't get sourcetype overrided by using a transform. I'm missing something, I'm guessing obvious, but not obvious to me!

inputs.conf

[monitor:///Users/admin/Documents/splunkDataToIndex/automation_logs/]  
disabled = 0  
followTail = 0  
index = automationlogs  

props.conf

[source::/Users/admin/Documents/splunkDataToIndex/automation_logs/...]  
TRANSFORMS-set_sourcetype_for_scriptlogs = set_sourcetype_for_scriptlogs  
priority = 10  

transforms.conf

[set_sourcetype_for_scriptlogs]  
SOURCE_KEY = MetaData:Source  
DEST_KEY = MetaData:Sourcetype  
REGEX = .*/(.*?)\..*  
FORMAT = Sourcetype::$1  
0 Karma

carmackd
Communicator

Are you trying to extract the sourcetype out of the source field value?

i.e. ---> /Users/admin/Documents/splunkDataToIndex/automation_logs/

If so, your regex isnt matching anything.

0 Karma
Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...