I have a index time transform which is a bit loose in what it matches. I would like to limit it to a whitelist of indexes that I want to match against. I would very much appreciate your help with creating a clean regular expression to achieve the goal.
So I think I want REGEX = match any event with a embedded field of the form index="SomeIndexName" where SomeIndexName in (App1,App2,App3).
My current transform
[MyTransform]
REGEX=.index="(.?)"
DEST_KEY=_MetaData:Index
FORMAT=$1
CLEAN_KEYS
MV_ADD=0
The OR operator for regex is the pipe:
REGEX= index="(App1|App2|App3)"
I changed .index to just index because I'm not sure you need it.
The OR operator for regex is the pipe:
REGEX= index="(App1|App2|App3)"
I changed .index to just index because I'm not sure you need it.
Yes. $1 will contain the value inside the parenthesis.
Will $1 still contain the field value?