Getting Data In

What happens if "DEST_KEY = MetaData:Host"?

ankithreddy777
Contributor

May I know the answers for the below questions.

what happens if DEST_KEY = MetaData:Host? Does the Host metadata replaced by new one?.
what happens if DEST_KEY = _raw? Does the entire _raw replaced?
what is default DEST_KEY?

1 Solution

lguinn2
Legend

Here is the documentation on the keys in transforms.conf
And here are the specific answers to your questions:

If DEST_KEY = MetaData:Host, then the FORMAT must be supplied in the form FORMAT=host::newName where newName is the new value for the host field.

If DEST_KEY = _raw, the entire raw data of the event is replaced with the contents of the FORMAT

There is no default DEST_KEY, but DEST_KEY is not required for all types of transforms.

View solution in original post

lguinn2
Legend

Here is the documentation on the keys in transforms.conf
And here are the specific answers to your questions:

If DEST_KEY = MetaData:Host, then the FORMAT must be supplied in the form FORMAT=host::newName where newName is the new value for the host field.

If DEST_KEY = _raw, the entire raw data of the event is replaced with the contents of the FORMAT

There is no default DEST_KEY, but DEST_KEY is not required for all types of transforms.

saurabh_tek11
Communicator

@ankithreddy777 DEST_KEY = _raw is generally used for masking the sensitive data (card numbers, PINs or IP addresses) which comes in _raw

This is supplemented with REGEX = (your regex e.g. to extract PIN) - for values which you want to mask in your raw data
and
FORMAT = $1PIN=####$2 masking the 4 digit PIN with 4 hashes.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

Modernize your Splunk Apps – Introducing Python 3.13 in Splunk

We are excited to announce that the upcoming releases of Splunk Enterprise 10.2.x and Splunk Cloud Platform ...

Step into “Hunt the Insider: An Splunk ES Premier Mystery” to catch a cybercriminal ...

After a whole week of being on call, you fell asleep on your keyboard, and you hit a sequence of buttons that ...