Getting Data In

What happens if "DEST_KEY = MetaData:Host"?

ankithreddy777
Contributor

May I know the answers for the below questions.

what happens if DEST_KEY = MetaData:Host? Does the Host metadata replaced by new one?.
what happens if DEST_KEY = _raw? Does the entire _raw replaced?
what is default DEST_KEY?

1 Solution

lguinn2
Legend

Here is the documentation on the keys in transforms.conf
And here are the specific answers to your questions:

If DEST_KEY = MetaData:Host, then the FORMAT must be supplied in the form FORMAT=host::newName where newName is the new value for the host field.

If DEST_KEY = _raw, the entire raw data of the event is replaced with the contents of the FORMAT

There is no default DEST_KEY, but DEST_KEY is not required for all types of transforms.

View solution in original post

lguinn2
Legend

Here is the documentation on the keys in transforms.conf
And here are the specific answers to your questions:

If DEST_KEY = MetaData:Host, then the FORMAT must be supplied in the form FORMAT=host::newName where newName is the new value for the host field.

If DEST_KEY = _raw, the entire raw data of the event is replaced with the contents of the FORMAT

There is no default DEST_KEY, but DEST_KEY is not required for all types of transforms.

saurabh_tek11
Communicator

@ankithreddy777 DEST_KEY = _raw is generally used for masking the sensitive data (card numbers, PINs or IP addresses) which comes in _raw

This is supplemented with REGEX = (your regex e.g. to extract PIN) - for values which you want to mask in your raw data
and
FORMAT = $1PIN=####$2 masking the 4 digit PIN with 4 hashes.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Unlock What’s Next: The Splunk Cloud Platform at .conf25

In just a few days, Boston will be buzzing as the Splunk team and thousands of community members come together ...