Hi,
I want to send data to x index if the host is non prod and host name is like abc-nprd* for /var/log
However, would like to send data to y index if host is prod and host name is like abc-prd* for /var/log
Don't want to create multiple apps for prod and non prod. So is there is way I can achieve the above by deploying the same app to prod and non prod.
Any help appreciated.
Thanks.
Hi @Abha111 ,
Will the host name parameter come inside the events as well? If yes. you can simply define a regex in transforms.conf to route it to specific index.
Example below.
props.conf
[your_sourcetype]
enter your props
TRANSFORMS-routing=set_nonprod,setprod
transforms.conf
[set_nonprod]
REGEX = abc-nprd*
DEST_KEY = _MetaData:Index
FORMAT = index_x
[setprod]
REGEX = abc-prd*
DEST_KEY = _MetaData:Index
FORMAT = index_y
Try this. Let me know for any further questions. If this works, give thumbs-up 🙂
Happy Splunking!!