Splunk Search

How to configure splunk HF to route the events which does not include a keyword?

SK_
New Member

Hello Community,

We have 2 target groups to route events.(2 indexers, one is ours and other 3rd party)

i want to configure Splunk HF to route events which does not contain particular keyword, ( like a NOT operation) to one target group and all events to other target group

For example below should be my transforms.conf except that i am not sure about the Regex command.

transforms.conf

[specific_events]
REGEX = "NOT ping"
DEST_KEY = _TCP_ROUTING
FORMAT = specific_event_targetgroup

[all_events]

REGEX = .
DEST_KEY = _TCP_ROUTING
FORMAT = all_event_targetgroup

 

I have tried few Regex commands ^(?!.*ping).* and ^((?!ping).)*$ which worked in regex101 and splunk UI search but not in the conf files. Once i have applied these regex commands to conf file, no events were reaching indexers. Can someone help on this?

 

 

 

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Splunk APM & RUM | Upcoming Planned Maintenance

There will be planned maintenance of the streaming infrastructure for Splunk APM and Splunk RUM in the coming ...

Part 2: Diving Deeper With AIOps

Getting the Most Out of Event Correlation and Alert Storm Detection in Splunk IT Service Intelligence   Watch ...

User Groups | Upcoming Events!

If by chance you weren't already aware, the Splunk Community is host to numerous User Groups, organized ...