Getting Data In

Split syslog input into multiple indexes

hollow
Explorer

I'm trying to split messages that come into splunk via UDP:514 (single input, single sourcetype) into multiple indexes based on a regex that should be applied to the _raw message.

I've tried several suggestions i've found in splunk-base but nothing seems to work 😞

My current configuration looks like this:

inputs.conf

[tcp://8514]
connection_host = ip
sourcetype = syslog

props.conf

[syslog]
TRANSFORMS-index=route-to-index

transforms.conf

[route-to-index]
REGEX = ^<\d+>(app|pubsub|updater)(?:\[(\d+)\])?:\s
FORMAT = index::myindex
WRITE_META = true

The inputs.conf is in etc/system/local/inputs.conf, props and transforms are in a custom app.

The goal is to filter based on the process name for now. The regex definitely matches the messages, but nothing appears in myindex.

1 Solution

dart
Splunk Employee
Splunk Employee

You're pretty close. In your

transforms.conf

[route-to-index]
REGEX = ^<\d+>(app|pubsub|updater)(?:\[(\d+)\])?:\s
FORMAT = myindex
DEST_KEY = _MetaData:Index

Should do the trick.

View solution in original post

dart
Splunk Employee
Splunk Employee

You're pretty close. In your

transforms.conf

[route-to-index]
REGEX = ^<\d+>(app|pubsub|updater)(?:\[(\d+)\])?:\s
FORMAT = myindex
DEST_KEY = _MetaData:Index

Should do the trick.

hollow
Explorer

i could swear that i also had this variant in my configs before. but it seems to work now, thanks a lot! 🙂

0 Karma

zugji
Path Finder

Is this sill working if in inputs.conf an index is defined?
Let's say:

index = main
0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mile High Learning with Splunk University, Denver, Colorado

If Denver is known for its mile-high elevation, Splunk University is about to raise the bar on technical ...

IT Service Intelligence 5.0 Series: Your Guide to the June Launch

We are excited to announce the June release of Splunk IT Service Intelligence (ITSI) 5.0. This update ...

Agent Mode Engaged! Enchaining Agentic Operations with Splunk AI Assistant 2.0

    Are you ready to transform how your team handles complex data requests? We invite you to our upcoming ...