Getting Data In
Highlighted

Re: Routing events to a specific index based on a field value via transforms and props not working as expected

Communicator

inputs.conf in $SPLUNK_HOME/etc/apps/search/local has all of my custom defined data inputs. This one in particular is [udp://515] and lists:

[udp://515]
index = indexA
source = sourceA
sourcetype = sourcetypeA
connection_host = dns

That being said, should this inputs.conf be located elsewhere, such as in $SPLUNK_HOME/etc/system/local where the props.conf and transforms.conf are located, or should I move props and transforms to be with this inputs? I wouldn't think it matters honestly.

If I run btool as you suggested it pulls props from $SPLUNK_HOME/etc/system/local and $SPLUNK_HOME/etc/system/default, but the transforms it refers to is from $SPLUNK_HOME/etc/system/local

0 Karma
Highlighted

Re: Routing events to a specific index based on a field value via transforms and props not working as expected

SplunkTrust
SplunkTrust

Do you have a sample event (sanatized) that you can share? all of these things should be working. You can keep them in system/local, that's fine for now.

Join us on IRC, #splunk on efnet.org, and we can discuss real-time what and how.

0 Karma
Highlighted

Re: Routing events to a specific index based on a field value via transforms and props not working as expected

Path Finder

Could you do it using props and transforms?

0 Karma