Splunk Enterprise

Alternatives to the way TA parses the data ?

neerajs_81
Builder

Hi All, 
What are our options if we are not content with the way a TA extracts fields out of our raw data ?  We  are seeing issues with the way AWS Add-on extracts the values for one of the log sources from AWS .  We are using the latest version of their TA as well.   What can we do from our side to correct the field extractions  ?   AWS Data comes in JSON format and one of the fields is messed up.

Labels (1)
Tags (1)
0 Karma
1 Solution

richgalloway
SplunkTrust
SplunkTrust

Yes.  You'll have the original props.conf and transforms.conf in /default and your changes will be in /local.  The files in /local should contain only the stanza name(s) and the settings you're changing.  No need to replicate the entire file or stanza.

---
If this reply helps you, Karma would be appreciated.

View solution in original post

richgalloway
SplunkTrust
SplunkTrust

TAs can be modified to suit your needs.  Copy the offending extraction to the TA's local directory and change it as necessary.  Then restart Splunk for it to take effect.

Be aware that doing this means you own that extraction.  If the TA updates it in the future the new extraction will not apply because of the local override.  You can, of course, delete the local version if it's no longer needed.

---
If this reply helps you, Karma would be appreciated.

neerajs_81
Builder

Do you mean copy the stanzas from props.conf or transform.conf of the TA and then create another copy in /local folder that suits our needs?

0 Karma

richgalloway
SplunkTrust
SplunkTrust

Yes.  You'll have the original props.conf and transforms.conf in /default and your changes will be in /local.  The files in /local should contain only the stanza name(s) and the settings you're changing.  No need to replicate the entire file or stanza.

---
If this reply helps you, Karma would be appreciated.
Get Updates on the Splunk Community!

.conf25 Community Recap

Hello Splunkers, And just like that, .conf25 is in the books! What an incredible few days — full of learning, ...

Splunk App Developers | .conf25 Recap & What’s Next

If you stopped by the Builder Bar at .conf25 this year, thank you! The retro tech beer garden vibes were ...

Congratulations to the 2025-2026 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...