Splunk Search

REGEX not working in transforms.conf

jhallur_splunk
Splunk Employee
Splunk Employee

Here is my event:

Contact=" (Contact){ Id -- '123' Email -- '[email protected]' Name -- 'Johnny blah' Phone -- '3333337856' }”

my props.conf

[ST_CONTACT_INFO]
BREAK_ONLY_BEFORE = Contact=
MAX_TIMESTAMP_LOOKAHEAD = 150
REPORT-contact1 = report-contactdetails
NO_BINARY_CHECK = 1
pulldown_type = 1

my transforms.conf

[report-contactdetails]
SOURCE_KEY = Contact
REGEX = [\s]([\w]+)[\s]--[\s]\'([^\']+)
FORMAT = $1::$2
MV_ADD = true

The fields like Id , Email, Name and Phone numbers are not auto extracted. The REGEX works fine and tested on regex101.com , check at http://regex101.com/r/tP2wB5/2
When I put the configuration in props.conf and transforms.conf, why it is not working? I have ensured that I gave the correct SOURCETYPE for the input.

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

So it seems the field Contact isn't available at the time of that REPORT application.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Yup, done.

0 Karma

jhallur_splunk
Splunk Employee
Splunk Employee

Please put your answer in the answer text box below so that I can accept it.

martin_mueller
SplunkTrust
SplunkTrust

So it seems the field Contact isn't available at the time of that REPORT application.

jhallur_splunk
Splunk Employee
Splunk Employee

Yes, it worked, but this overwrites the originally auto extracted field "Contact" with value single quote only. i.e Contact="

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

To narrow possible causes down please comment out the SOURCE_KEY - your extraction should still match on the _raw text as shown by your URL.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Your Feedback. Our Roadmap. Visit the PX Feedback Booth at .conf26

You use Splunk every day, come and help shape what's next.  Save Your Seat: Product-Focused Sessions at ...

Agentic SOC Triage: Investigating Splunk ES Notables with MCP Server and a Local LLM

The Problem: Too Many Alerts, Too Little Context Security operations teams running Splunk Enterprise Security ...

Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas

Watch Now Painting a Clearer Picture: Creating Cross-Domain Visibility with AI Canvas     Do you ever feel ...