Getting Data In

Transform field extraction work from default but not from local

jeremyhagand61
Communicator

I'm using the Splunk TA for Symantec Endpoint Protection 2.3.0 and for the latest version of SEP some of the log file formats have changed and so the field extractions aren't working. I've taken the REGEX from the default\transforms.conf file and modified it and tested it using rex and all is works.

On the search head I copied the transforms.conf file from default to local (inside the app) however the field extractions don't work. So I tried putting the updated extraction directly into the default\transforms.conf file and they now work.

In both of the above cases running
.\splunk.exe cmd btool --app=Splunk_TA_symantec-ep transforms list

Displayed the updated REGEX

Can anyone shed some light on why this might be the case?

Do I need to update the local.meta file? If so, what should I put in there?

0 Karma

sonny_monti
Path Finder

Check your escape characters, some working using the rex command does not work in conf files. for example backslashes.
Check this post

0 Karma

jeremyhagand61
Communicator

Rex works in one transform.conf file, but not in another. Nothing wrong with the rex.

0 Karma

harsmarvania57
Ultra Champion

Hi,

After changing/adding configuration in <app>/local/transforms.conf have you restarted Splunk or used /debug/refresh endpoint to reload configuration ?

0 Karma

jeremyhagand61
Communicator

See from my OP that when I put them in default\transforms it works. So yes I have.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Mastering Threat Intelligence in ES 8.5, Splunk AI Assistant v2, and More from Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...

Break the Build: Inside the KubeDoom Lounge at .conf26

    You step up to the machine. The pixelated corridors of a certain 1993 FPS load in front of you, EMP Pulse ...

Splunk Auto Ingestion Parallel Pipeline Scaling

Why this feature matters Many Splunk environments experience ingestion pressure long before the host is fully ...