Getting Data In

Problems with setting sourcetype through transformations.conf

quixand
Path Finder

This is driving me mad - have gone through the documentation and responses to queries in here but still can't get sourcetype overrided by using a transform. I'm missing something, I'm guessing obvious, but not obvious to me!

inputs.conf

[monitor:///Users/admin/Documents/splunkDataToIndex/automation_logs/]  
disabled = 0  
followTail = 0  
index = automationlogs  

props.conf

[source::/Users/admin/Documents/splunkDataToIndex/automation_logs/...]  
TRANSFORMS-set_sourcetype_for_scriptlogs = set_sourcetype_for_scriptlogs  
priority = 10  

transforms.conf

[set_sourcetype_for_scriptlogs]  
SOURCE_KEY = MetaData:Source  
DEST_KEY = MetaData:Sourcetype  
REGEX = .*/(.*?)\..*  
FORMAT = Sourcetype::$1  
0 Karma

carmackd
Communicator

Are you trying to extract the sourcetype out of the source field value?

i.e. ---> /Users/admin/Documents/splunkDataToIndex/automation_logs/

If so, your regex isnt matching anything.

0 Karma
Get Updates on the Splunk Community!

Splunk Mobile: Your Brand-New Home Screen

Meet Your New Mobile Hub  Hello Splunk Community!  Staying connected to your data—no matter where you are—is ...

Introducing Value Insights (Beta): Understand the Business Impact your organization ...

Real progress on your strategic priorities starts with knowing the business outcomes your teams are delivering ...

Enterprise Security (ES) Essentials 8.3 is Now GA — Smarter Detections, Faster ...

As of today, Enterprise Security (ES) Essentials 8.3 is now generally available, helping SOC teams simplify ...