hi,
Can someone please explain me the below transforms.conf . I read the documentation ,but it's not clear to me .
[route-index-abc]
REGEX = (.*) ( what is the use of REGEX)
DEST_KEY = _MetaData:Index ( what is the use DEST_KEY)
FORMAT = server_application ( what is the use of FORMAT)
The transforms.conf entry that you've is applied to each event of a sourcetype, source or host.
So basically what it's doing here is, for each event, change the value of index (represented as _MetaData:Index in transforms.conf) with value server_application, regardless of what it's original value was.
Its' actually solving this problem
https://answers.splunk.com/answers/246672/how-can-i-override-an-index-name-based-on-sourcety.html