Home
Join the Community
Getting Started
Welcome
Join Slack
Be a Splunk Champion
SplunkTrust
Super User Program
Badges
Tell us what you think
Splunk Love
Community Feedback
Learn Splunk
Learning Paths
Training & Certification
Training + Certification Discussions
Training & Certification Blog
AppDynamics Knowledge Base
Share a Tip
Find Answers
Splunk Administration
Getting Data In
Deployment Architecture
Monitoring Splunk
Using Splunk
Splunk Search
Dashboards & Visualizations
Splunk Platform
Splunk Enterprise
Splunk Cloud Platform
Splunk AppDynamics
Apps & Add-ons
Splunk Development
All Apps and Add-ons
Premium Solutions
Splunk Enterprise Security
Splunk Observability Cloud
Splunk ITSI
Splunk SOAR
News & Events
Blog & Announcements
Community Blog
Product News & Announcements
Events and Contests
Tech Talks: Technical Deep Dives
Office Hours: Ask the Experts
User Groups
Resources
.conf25
SplunkBase
Developers
Documentation
Splunk Ideas
Splunk Events
Sign In
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for
Show
only
|
Search instead for
Do you mean
Getting Data In
×
Are you a member of the Splunk Community?
Sign in or Register
with your Splunk account to get your questions answered, access valuable resources and connect with experts!
Community
Category
Board
Knowledge Base
Users
Turn on suggestions
Auto-suggest helps you quickly narrow down your search results by suggesting possible matches as you type.
Showing results for
Show
only
|
Search instead for
Do you mean
Ask a Question
Find Answers
:
Splunk Administration
:
Getting Data In
:
Re: Use RegEx to set sourcetype on UF where events...
Mark as New
Bookmark Message
Subscribe to Message
Subscribe to RSS Feed
Permalink
Print
Report Inappropriate Content
Re: Use RegEx to set sourcetype on UF where events are in a JSON format
cpetterborg
SplunkTrust
04-25-2020
09:05 AM
«
Previous Message
Next Message
»
Subject
Author
Karma
Views
Posted
Use RegEx to set sourcetype on UF where events are...
donaldwayne1975
0
2001
04-24-2020
08:57 AM
Re: Use RegEx to set sourcetype on UF where events...
cpetterborg
0
1825
04-25-2020
09:05 AM
Re: Use RegEx to set sourcetype on UF where events...
to4kawa
0
1824
04-24-2020
04:34 PM
«
Message Listing
«
Previous Topic
Next Topic
»
Mark as New
Bookmark Message
Subscribe to Message
Subscribe to RSS Feed
Permalink
Print
Report Inappropriate Content
Use RegEx to set sourcetype on UF where events are in a JSON format
donaldwayne1975
Path Finder
04-24-2020
08:57 AM
Tags
(5)
Tags:
json
props.conf
sourcetype_regex
splunk-enterprise
transforms.conf
Mark as New
Bookmark Message
Subscribe to Message
Subscribe to RSS Feed
Permalink
Print
Report Inappropriate Content
Re: Use RegEx to set sourcetype on UF where events are in a JSON format
cpetterborg
SplunkTrust
04-25-2020
09:05 AM
Mark as New
Bookmark Message
Subscribe to Message
Subscribe to RSS Feed
Permalink
Print
Report Inappropriate Content
Re: Use RegEx to set sourcetype on UF where events are in a JSON format
to4kawa
Ultra Champion
04-24-2020
04:34 PM
Get Updates on the Splunk Community!
Building Reliable Asset and Identity Frameworks in Splunk ES
Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...
Cloud Monitoring Console - Unlocking Greater Visibility in SVC Usage Reporting
For Splunk Cloud customers, understanding and optimizing Splunk Virtual Compute (SVC) usage and resource ...
Automatic Discovery Part 3: Practical Use Cases
If you’ve enabled Automatic Discovery in your install of the Splunk Distribution of the OpenTelemetry ...
Read our Community Blog >