Hi All
I have a sourcetype in which we have some events with a keyword like asdf. In some events it comes in between and some events at the end.
I need to forward all these logs to another sourcetype with props and transforms.
[generic_sourcetype_routing_asdf]
REGEX =
DEST_KEY = MetaData:Sourcetype
FORMAT = sourcetype::asdf_logs
props.conf
[current_sourcetype]
TRANSFORMS-sourcetype_routing = generic_sourcetype_routing_asdf
In the REGEX part I would like to know if only keeping asdf or *asdf * would work. I can't put the regex for complete log format since there are multiple formats. So I need to inform splunk to pass any event with asdf anywhere in it should be forwarded to the new one. Please suggest.
Thanks
Maria Arokiaraj
*asdf* is not a valid regular expression. Use asdf. There is an implied wildcard at the beginning and end of every regex unless specified otherwise with ^ and/or $.
regex101.com is a great place to test expressions.
Just adding the keyword asdf worked for me 🙂 Thanks
*asdf* is not a valid regular expression. Use asdf. There is an implied wildcard at the beginning and end of every regex unless specified otherwise with ^ and/or $.
regex101.com is a great place to test expressions.