Hi,
We collect windows performance logs. After the update to 7.2.0, each performance counter with a Space in its name is being filled with an underscore making us change all the alerts and searches.
Can you please help how to fix this issue.
Thanks,
Field names with spaces are evil, but the setting that you need is CLEAN_KEYS
:
https://docs.splunk.com/Documentation/Splunk/latest/Admin/Transformsconf#CLEAN_KEYS
CLEAN_KEYS = [true|false]
* NOTE: This setting is only valid for search-time field extractions.
* Optional. Controls whether Splunk software "cleans" the keys (field names) it
extracts at search time. "Key cleaning" is the practice of replacing any
non-alphanumeric characters (characters other than those falling between the
a-z, A-Z, or 0-9 ranges) in field names with underscores, as well as the
stripping of leading underscores and 0-9 characters from field names.
* Add CLEAN_KEYS = false to your transform if you need to extract field
names that include non-alphanumeric characters, or which begin with
underscores or 0-9 characters.
* Default: true
can you share your input.conf