Splunk Search
Highlighted

understanding the transforms.conf

Path Finder

hi,
Can someone please explain me the below transforms.conf . I read the documentation ,but it's not clear to me .

[route-index-abc]
REGEX = (.*) ( what is the use of REGEX)
DESTKEY = _MetaData:Index ( what is the use DESTKEY)
FORMAT = server_application ( what is the use of FORMAT)

0 Karma
Highlighted

Re: understanding the transforms.conf

SplunkTrust
SplunkTrust

The transforms.conf entry that you've is applied to each event of a sourcetype, source or host.

  • The REGEX is a regular expression that tries to find a match from the value of SOURCE_KEY (an attribute which has default value as _raw, your raw data). A dot means it'll match everything (the transform will be done for all events).
  • DEST_KEY - it provides a Splunk field (that are available at the time of parsing) where the transformation will be applied.
  • FORMAT - it's a value that will be applied to value of DEST_KEY

So basically what it's doing here is, for each event, change the value of index (represented as MetaData:Index in transforms.conf) with value serverapplication, regardless of what it's original value was.

0 Karma
Highlighted

Re: understanding the transforms.conf

SplunkTrust
SplunkTrust
0 Karma
Speak Up for Splunk Careers!

We want to better understand the impact Splunk experience and expertise has has on individuals' careers, and help highlight the growing demand for Splunk skills.