Splunk Search

I disabled a transforms.conf stanza in Splunk Web, but why is the regex field extraction still effective?

hylam
Contributor

I have disabled the transform stanza in the GUI, but the regex field extractions are still effective. What's wrong?

http://docs.splunk.com/Documentation/Splunk/6.0/Knowledge/Createandmaintainsearch-timefieldextractio...

[<spec>]
REPORT-<class> = <unique_transform_stanza_name1>, <unique_transform_stanza_name2>,...

props.conf:REPORT-apNameList = apNameList
transforms.conf:[apNameList]
transforms.conf:disabled = 1

0 Karma

woodcock
Esteemed Legend

There are things that create fields automatically; you should make sure that you set KV_MODE = none also. Post an example event and the fields that shouldn't be there.

0 Karma

frmaasdam
Path Finder

You can check your eventually combined transforms.conf by executing the command.
splunk cmd btool transforms list.
Then you can check which transforms are active or not.

0 Karma

krish3
Contributor

I do not see any disabled argument in stanza's of transforms.conf

Just try commenting out the configuration and restart the instance.

Let me know how it goes... 🙂

hylam
Contributor

GUI problem?

0 Karma

krish3
Contributor

What do you mean by GUI problem?

0 Karma

hylam
Contributor

I navigated to Fields » Field transformations. Then I clicked disable in that row. Has the GUI produced "disabled = 1" which is undefined in transforms.conf.spec?

0 Karma

krish3
Contributor

Okay did you restart the instance??

0 Karma

hylam
Contributor

I did not restart the instance. After disabling the transform stanza thru the GUI, I hit http://localhost:8000/debug/refresh.

0 Karma

krish3
Contributor

Try this http://yoursplunkserver:8000/en-us/debug/refresh?entity=admin/transforms-lookup

Or if not please try a restart that should fix the issue.

0 Karma

hylam
Contributor

I tried all 3. The regex transform is still working. What is the "disabled = 1" in transforms.conf for? Why is the GUI for disabling transform stanzas there?

0 Karma
Get Updates on the Splunk Community!

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...