Splunk Search

Route specific events to a relative index

wayn23
Explorer

I need to retain events for different periods of time based on content. I have created indexes with different retentions, for example, audit_1YR, audit_2YR

I am using the advice in http://docs.splunk.com/Documentation/Splunk/6.6.3/Indexer/Setupmultipleindexes#Send_events_to_specif...

I can successfully redirect to different absolute indexes using config like the following on the Indexer
$SPLUNK_HOME/etc/system/local/props.conf:
[my_sourcetype]
TRANSFORMS-index = Retain2Year

$SPLUNK_HOME/etc/system/local/transforms.conf:
[Retain2Year]
REGEX = (2YR)
DEST_KEY = _MetaData:Index
FORMAT = Audit_2YR

What I would like to be able to do is make the new index name be relative to the passed index name set in the Splunk Universal Forwarder, by just suffixing the index name. For example, something like
FORMAT = existingIndexName_2YR

Is that possible? How can the existing index name be referenced in the FORMAT statement? I have tried the following, which all failed
FORMAT = $index.$1
FORMAT = index::$index.$1
FORMAT = _meta:index.$1

0 Karma
1 Solution

wayn23
Explorer

I have this working now! The right reference was $0. The following statement is working for me
FORMAT=$0_2YR

I found the information at http://docs.splunk.com/Documentation/SplunkCloud/6.6.1/Data/Configureindex-timefieldextraction

View solution in original post

0 Karma

wayn23
Explorer

I have this working now! The right reference was $0. The following statement is working for me
FORMAT=$0_2YR

I found the information at http://docs.splunk.com/Documentation/SplunkCloud/6.6.1/Data/Configureindex-timefieldextraction

0 Karma

DalJeanis
Legend

@wayn23 - We converted your comment to an answer, so you can mark the question as closed by accepting it. Happy splunking!

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Index This | What travels the world but is also stuck in place?

April 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Discover New Use Cases: Unlock Greater Value from Your Existing Splunk Data

Realizing the full potential of your Splunk investment requires more than just understanding current usage; it ...

Continue Your Journey: Join Session 2 of the Data Management and Federation Bootcamp ...

As data volumes continue to grow and environments become more distributed, managing and optimizing data ...