Hello Community,
We have 2 target groups to route events.(2 indexers, one is ours and other 3rd party)
i want to configure Splunk HF to route events which does not contain particular keyword, ( like a NOT operation) to one target group and all events to other target group
For example below should be my transforms.conf except that i am not sure about the Regex command.
transforms.conf
[specific_events]
REGEX = "NOT ping"
DEST_KEY = _TCP_ROUTING
FORMAT = specific_event_targetgroup
[all_events]
REGEX = .
DEST_KEY = _TCP_ROUTING
FORMAT = all_event_targetgroup
I have tried few Regex commands ^(?!.*ping).* and ^((?!ping).)*$ which worked in regex101 and splunk UI search but not in the conf files. Once i have applied these regex commands to conf file, no events were reaching indexers. Can someone help on this?