- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
set indexes dynamically in inputs.conf
sbattista
Explorer
08-02-2021
07:25 AM
I was able to set indexes dynamically in inputs.conf based off the source path folder name however, it seems like its not working in Splunk cloud. I have tried to upload a app with the props and transforms and also tried to use a HWF as well. hoping someone out there might be able to help.
this is basically what my conf files look like-
-props-
[source::\\fileshare\\folder\\...]
TRANSFORMS=send_to_index_by_source
-transforms-
[send_to_index_by_source]
SOURCE_KEY=_MetaData:Source
REGEX=\\\wfileshare\\\wfolder\\(\w+)
DEST_KEY=_MetaData:Index
FORMAT=$1
-inputs-
[monitor://\\fileshare\folder\...\test15.txt]
disabled=false
recursive=true
sourcetype=test15
