Hi all,
I need some leads on an issue. I am having trouble in data forwarding from splunk HF to 3rd party. My prop.conf file below:
[host::hostname]
TRANSFORMS-weblog-matrix = send_to_syslog_EFH,send_to_index.
But this is forwarding all the logs from the host. but instead I want to send one of the sourcetype from the host.
Is it possible to filter by both hostname and sourcetype? If so, please peovide some sample props.conf and transformas.conf.
Thanks
Hi graju89,
see this https://docs.splunk.com/Documentation/Splunk/7.3.2/Forwarding/Forwarddatatothird-partysystemsd and https://docs.splunk.com/Documentation/Splunk/7.3.2/Admin/Transformsconf
Anyway to filter for two parameters there are two ways:
SOURCE_KEY = MetaData:Host
option in your transforms.conf, e.g. something like this:props.conf
[your_sourcetype]
TRANSFORMS-weblog-matrix = send_to_syslog_EFH,send_to_index
transforms.conf
[send_to_syslog_EFH]
SOURCE_KEY = MetaData:Host
REGEX = your_host
DEST_KEY=_SYSLOG_ROUTING
FORMAT=my_syslog_group
Ciao.
Giuseppe