When I configure INGEST_EVAL to replace _raw with something else, it duplicates the event.
Splunk Enterprise Version 8.2.1
props.conf:
transforms.conf
Output:
I found a workaround to circumvent this bug.
tranforms.conf
Because I notices that one of the duplicates has an indexed field "timestamp::none" and the other does not. With this I am routing only one of the to the nullQueue and keep the other.
I found a workaround to circumvent this bug.
tranforms.conf
Because I notices that one of the duplicates has an indexed field "timestamp::none" and the other does not. With this I am routing only one of the to the nullQueue and keep the other.