Getting Data In

Route index data based on source

rreatiga
Observer

Hi,

Is it possible using props.conf and transforms.conf to route some data on an index based on the source field?

Let's say index1 contains a lot of sources, in some sources it contains certain words in the path for example

(source="*dev-ksm*" OR source="*int-ksm*" OR source="*qa-ksm*" OR source="*amq-*-ksm*")

For this scenario I'd like to route events that their source contains the above matching sources to an index2

Was thinking in something like this:

props.conf

[index::current_index]
TRANSFORMS-routing=filter-to-new_index

 

transforms.conf

[filter-to-new_index]
DEST_KEY = _MetaData:Index 
SOURCE_KEY = MetaData:Source 
REGEX = (?i)(.*dev-ksm.*|.*int-ksm.*|.*qa-ksm.*|.*amq-.*-ksm.*)
FORMAT = new_index

 

Does not seem to be currently working. Hence the question if its possible to do something like this.

 

Thanks in advance.

 

 

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rreatiga,

in the header of the props.conf stanza, you cannot use "index::current_index" but only sourcetype or source or host fields.

for source and host, you can also use jolly char, something like this:

props.conf

[source::*dev-ksm*]
TRANSFORMS-routing=filter-to-new_index

[source::*int-ksm*]
TRANSFORMS-routing=filter-to-new_index

[source::*qa-ksm*]
TRANSFORMS-routing=filter-to-new_index

[source::*amq-*-ksm*]
TRANSFORMS-routing=filter-to-new_index

transorms.conf

[filter-to-new_index]
DEST_KEY = _MetaData:Index 
REGEX = .
FORMAT = new_index

Ciao.

Giuseppe

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...

[Puzzles] Solve, Learn, Repeat: Tiling

This puzzle (first published here) is based on finding groups of tessellated tiles (inspired by floor tiles I ...

SOK it to Me: Top 3 Benefits of Using Splunk Operator on Kubernetes that’ll Make ...

    Thursday, July 9, 2026  |  11:00AM–12:00PM PDT Duration: 1 hour (includes Q&A) Managing can feel like a ...