Getting Data In

partially rewrite event index name based on sourcetype value



I already know how to statically rewrite the index value based on a sourcetype.
Typically using something similar to:

But I have today a slightly more complex need.

events are generated on a HF as following:
- index = prefix-environment-default
- sourcetype = (5 different values)

per sourcetype, I need to rewrite the index as following:
- if sourcetype = sourcetype1 then "default" suffix in index name should be replaced by something else specific to this index
- but (this is the part I have not find how to manage yet)... the first part of the original index name should be changed... especially, the middle part (environment) will vary and should remain intact.

is it possible to apply kind of regex/sed to capture the "default" suffix and replace it by the suffix that match a given sourcetype ?
Then I would duplicate the transform to have one per sourcetype


0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...