Splunk Search

Transforms.conf: Need help combining regex (simple)?

the_wolverine
Champion

I'm sure this is really simple but I've been unable to figure out the syntax to combine these 2 regexes in my transforms.conf. Thus, I've split them into two separate stanzas:

[first]
REGEX=(?m)(ComputerName=HerComputer)
DEST_KEY=_MetaData:Index
FORMAT=new

[second]
REGEX=(?m)(ComputerName=HisLaptop)
DEST_KEY=_MetaData:Index
FORMAT=new
1 Solution

ziegfried
Influencer

How about this?

[combined]
REGEX=(?m)ComputerName=(HerComputer|HisLaptop)
DEST_KEY=_MetaData:Index
FORMAT=new

View solution in original post

ziegfried
Influencer

How about this?

[combined]
REGEX=(?m)ComputerName=(HerComputer|HisLaptop)
DEST_KEY=_MetaData:Index
FORMAT=new

the_wolverine
Champion

Thanks 🙂

0 Karma
Get Updates on the Splunk Community!

Application management with Targeted Application Install for Victoria Experience

  Experience a new era of flexibility in managing your Splunk Cloud Platform apps! With Targeted Application ...

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk + Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...