Getting Data In

Props and transforms: Order of execution of transforms for multiple stanza?

koshyk
Super Champion

AS per props.conf documentation

  • Use a comma-separated list to apply multiple transform stanzas to a single

    TRANSFORMS extraction. Splunk applies them in the list order. For example,
    this sequence ensures that the [yellow] transform stanza gets applied
    first, then [blue], and then [red]:
    [source::color_logs]
    TRANSFORMS-colorchange = yellow, blue, red

But I have an issue whereby I cannot put all the 3 transforms in single stanza.

 [source::color_logs] # say this assigns a yellow_colored_logs  sourcetype
TRANSFORMS-colorchange = yellow
[yellow_colored_logs]
TRANSFORMS-zcolorchange = blue,red

Will the above order work? So basically my question is will splunk handle transforms on serial order if I put in multiple stanza?

Tags (2)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi koshyk,
I suggest to use one method to transform your logs (e.g. sourcetypes)

[yellow_colored_logs]
 TRANSFORMS-zcolorchange1 = blue,red
[red_colored_logs]
 TRANSFORMS-zcolorchange2 = blue,yellow
[blue_colored_logs]
 TRANSFORMS-zcolorchange3 = red,yellow

testing order.

Bye.
Giuseppe

koshyk
Super Champion

@cusello thanks for that. I will test and let you know. Meantime, I will upvote and if its successful I will mark as answer

0 Karma
Get Updates on the Splunk Community!

Aligning Observability Costs with Business Value: Practical Strategies

 Join us for an engaging Tech Talk on Aligning Observability Costs with Business Value: Practical ...

Mastering Data Pipelines: Unlocking Value with Splunk

 In today's AI-driven world, organizations must balance the challenges of managing the explosion of data with ...

Splunk Up Your Game: Why It's Time to Embrace Python 3.9+ and OpenSSL 3.0

Did you know that for Splunk Enterprise 9.4, Python 3.9 is the default interpreter? This shift is not just a ...