Splunk Search

REGEX not working in transforms.conf

jhallur_splunk
Splunk Employee
Splunk Employee

Here is my event:

Contact=" (Contact){ Id -- '123' Email -- 'johnny@gmail.com' Name -- 'Johnny blah' Phone -- '3333337856' }”

my props.conf

[ST_CONTACT_INFO]
BREAK_ONLY_BEFORE = Contact=
MAX_TIMESTAMP_LOOKAHEAD = 150
REPORT-contact1 = report-contactdetails
NO_BINARY_CHECK = 1
pulldown_type = 1

my transforms.conf

[report-contactdetails]
SOURCE_KEY = Contact
REGEX = [\s]([\w]+)[\s]--[\s]\'([^\']+)
FORMAT = $1::$2
MV_ADD = true

The fields like Id , Email, Name and Phone numbers are not auto extracted. The REGEX works fine and tested on regex101.com , check at http://regex101.com/r/tP2wB5/2
When I put the configuration in props.conf and transforms.conf, why it is not working? I have ensured that I gave the correct SOURCETYPE for the input.

0 Karma
1 Solution

martin_mueller
SplunkTrust
SplunkTrust

So it seems the field Contact isn't available at the time of that REPORT application.

View solution in original post

martin_mueller
SplunkTrust
SplunkTrust

Yup, done.

0 Karma

jhallur_splunk
Splunk Employee
Splunk Employee

Please put your answer in the answer text box below so that I can accept it.

martin_mueller
SplunkTrust
SplunkTrust

So it seems the field Contact isn't available at the time of that REPORT application.

jhallur_splunk
Splunk Employee
Splunk Employee

Yes, it worked, but this overwrites the originally auto extracted field "Contact" with value single quote only. i.e Contact="

0 Karma

martin_mueller
SplunkTrust
SplunkTrust

To narrow possible causes down please comment out the SOURCE_KEY - your extraction should still match on the _raw text as shown by your URL.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...