I have a very small app that is installed in our Splunk Cloud instance.
in props.conf I have
[access_combined]
REPORT-access_combined = REPORT-extract_app_from_source
and in transforms.conf
[REPORT-extract_app_from_source]
SOURCE_KEY = source
REGEX = [regex to extract app attribute]
This has been working perfectly to extract the variable app from the source during searches.
I have made a separate unrelated update to the app and now I am getting a failure when Splunk Cloud is vetting the app.
check_pretrained_sourcetypes_have_only_allowed_transforms
- Only TRANSFORMS- or SEDCMD options are allowed for pretrained sourcetypes.
What is now the correct way to add these search time attributes?
Bump
Any update on this Craig?