Getting Data In

set indexes dynamically in inputs.conf

sbattista
Explorer

I was able to set indexes dynamically in inputs.conf based off the source path folder name however, it seems like its not working in Splunk cloud. I have tried to upload a app with the props and transforms and also tried to use a HWF as well. hoping someone out there might be able to help. 

 

this is basically what my conf files look like-

-props-

[source::\\fileshare\\folder\\...]
TRANSFORMS=send_to_index_by_source

 

-transforms-

[send_to_index_by_source]
SOURCE_KEY=_MetaData:Source
REGEX=\\\wfileshare\\\wfolder\\(\w+)
DEST_KEY=_MetaData:Index
FORMAT=$1

-inputs-

[monitor://\\fileshare\folder\...\test15.txt]
disabled=false
recursive=true
sourcetype=test15

 

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Pro Tips for First-Time .conf Attendees: Advice from SplunkTrust

Heading to your first .Conf? You’re in for an unforgettable ride — learning, networking, swag collecting, ...

Raise Your Skills at the .conf25 Builder Bar: Your Splunk Developer Destination

Calling all Splunk developers, custom SPL builders, dashboarders, and Splunkbase app creators – the Builder ...

Hunt Smarter, Not Harder: Discover New SPL “Recipes” in Our Threat Hunting Webinar

Are you ready to take your threat hunting skills to the next level? As Splunk community members, you know the ...