Getting Data In

how to write the props.conf stanze to test the transforms Regex?

pavanae
Builder

The following is transforms.conf in my search head

[a_b]
SOURCE_KEY = _meta
REGEX = (logtype::A.*(id::(123|456)|(id::789.*username!::[a-zA-Z]{2,3}-+.*?-ZLX))
DEST_KEY = _ghi
FORMAT = KLMN

Now how to write my props.conf in order to test the REGEX in the above transforms.conf works. Especially I would like to see if the id=789 and username not equall to the string that ends with -ZLX?

0 Karma
1 Solution

p_gurav
Champion

To props.conf, add the following lines:

[<sourcetype_name>]
TRANSFORMS-<class> = a_b

View solution in original post

0 Karma

woodcock
Esteemed Legend

Why are you using SOURCE_KEY = _meta? What do you think that your REGEX will match (and have you tested it with a tool like http://www.RegEx101.com)?

0 Karma

p_gurav
Champion

To props.conf, add the following lines:

[<sourcetype_name>]
TRANSFORMS-<class> = a_b
0 Karma

pavanae
Builder

Thanks @p_gurav. what does line 2 means. What should I specify there?

0 Karma

woodcock
Esteemed Legend

The <class> is fully arbitrary and the only requirement is that it must be unique across all configuration settings so do not pick a common/simple string.

0 Karma
Get Updates on the Splunk Community!

Observability | How to Think About Instrumentation Overhead (White Paper)

Novice observability practitioners are often overly obsessed with performance. They might approach ...

Cloud Platform | Get Resiliency in the Cloud Event (Register Now!)

IDC Report: Enterprises Gain Higher Efficiency and Resiliency With Migration to Cloud  Today many enterprises ...

The Great Resilience Quest: 10th Leaderboard Update

The tenth leaderboard update (11.23-12.05) for The Great Resilience Quest is out &gt;&gt; As our brave ...