Getting Data In

what is _meta in DEST_KEY field in transforms.conf and what it does and where it reflects and when we are writing _meta in DEST_KEY filed then we have to write $0 at start in FORMAT so what it means and why we have to do so?

dtk
Engager

i made whole transforms.conf and prop.conf for a data in splunk and analyse FORMAT in transform.conf with $0 and without it but nothing changes had reflected

markusspitzli
Communicator

According the transforms.conf documentation:
_meta : A space-separated list of metadata for an event.

Honestly I dont get your question, but I advice you to visit the documentation for transforms.conf. It has a lot of examples, which can help you. If not feel free to clarify your question.

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Please share your transforms.conf and props.conf settings.

---
If this reply helps you, Karma would be appreciated.
0 Karma
Get Updates on the Splunk Community!

What the End of Support for Splunk Add-on Builder Means for You

Hello Splunk Community! We want to share an important update regarding the future of the Splunk Add-on Builder ...

Solve, Learn, Repeat: New Puzzle Channel Now Live

Welcome to the Splunk Puzzle PlaygroundIf you are anything like me, you love to solve problems, and what ...

Building Reliable Asset and Identity Frameworks in Splunk ES

 Accurate asset and identity resolution is the backbone of security operations. Without it, alerts are ...