Getting Data In
Highlighted

trying to rename source at index time with transforms.conf

New Member

hello,

I want to change my source names in shorter ones. At first I had something that worked very well.
transforms.conf :

[shortsource]
SOURCE
KEY = Metadata:Source
REGEX =myregex(mycapturinggroup)
DEST_KEY = Metadata:Source
FORMAT = source::$1

But then i had to change my Splunk version, (the new one is 7.1.1), and i got an error when checking my configuration files : "undocumented key in transforms.conf ; stanza='shortsource' setting='SOURCEKEY'. Above you can see what I tried according to the splunk documentation :

[shortsource]
SOURCE
KEY = Metadata:Source
REGEX = myregex(mycapturinggroup)
DEST_KEY = Metadata:Source
FORMAT = source::$1

[acceptedkeys]
is
accepted = Metadata:Source

After restart, I don't have error anymore, but the source is not changing on my new indexed data.
Of course i have the appropriate stanza in porps.conf :

[mysourcetype]
TRANSFORMS-source = short
source

Thank you for your help!

0 Karma
Highlighted

Re: trying to rename source at index time with transforms.conf

Communicator

Try MetaData:Source with capital D.

 [short_source]
SOURCE_KEY = MetaData:Source
REGEX = myregex(my_capturing_group)
DEST_KEY = MetaData:Source
FORMAT = source::$1