Both of the above regex searches aren't filtering anything out. Here's a sample event.
endpoint="https://xxx.service-now.com/",business_duration="1970-01-01 00:00:00",start_time="2017-11-21 09:21:32",duration="1970-01-01 00:00:00",sys_updated_on="2017-11-21 09:21:33",has_breached="false",sys_created_on="2017-11-21 09:21:33",sys_id="d6f9a8s7d6f9a78sd6f9a78sd6f9a78s",sys_tags="",end_time="",pause_time="",task="sd9f8g6s9df8g69sd8f7g6sdfgs9df87",planned_end_time="2017-11-28 09:21:32",active="true",pause_duration="",sla="xyz",original_breach_time="2017-11-28 09:21:32",percentage="0",sys_mod_count="0",sys_updated_by="asdf",business_time_left="1970-01-03 02:00:00",stage="in_progress",timezone="Europe/London",schedule="asd9f8asd9f78as6d9f876sd9f786asd",business_percentage="0",time_left="1970-01-08 00:00:00",business_pause_duration="",sys_created_by="asdf"
host = splunk source = https://xxx.service-now.com/ sourcetype = snow:task_sla
Here's a btool snippet of my transforms.conf:
[setnull]
CAN_OPTIMIZE = True
CLEAN_KEYS = True
DEFAULT_VALUE =
DEST_KEY = queue
FORMAT = nullQueue
KEEP_EMPTY_VALS = False
LOOKAHEAD = 4096
MV_ADD = False
REGEX = .
SOURCE_KEY = _raw
WRITE_META = False
[setparsing]
CAN_OPTIMIZE = True
CLEAN_KEYS = True
DEFAULT_VALUE =
DEST_KEY = queue
FORMAT = indexQueue
KEEP_EMPTY_VALS = False
LOOKAHEAD = 4096
MV_ADD = False
REGEX = sla\=\"abc\"
SOURCE_KEY = _raw
WRITE_META = False
Btool snippet of props.conf:
[snow:task_sla]
ANNOTATE_PUNCT = True
AUTO_KV_JSON = true
BREAK_ONLY_BEFORE =
BREAK_ONLY_BEFORE_DATE = True
CHARSET = AUTO
DATETIME_CONFIG = \etc\datetime.xml
FIELDALIAS-snow:task_sla:tak_sys_id = task AS task_sys_id
HEADER_MODE =
LEARN_SOURCETYPE = true
LINE_BREAKER_LOOKBEHIND = 100
LOOKUP-sla_supplier_lookup = sla_supplier_lookup sys_id AS sla OUTPUTNEW name AS sla_definition priority sla_supplier
MAX_DAYS_AGO = 2000
MAX_DAYS_HENCE = 2
MAX_DIFF_SECS_AGO = 3600
MAX_DIFF_SECS_HENCE = 604800
MAX_EVENTS = 256
MAX_TIMESTAMP_LOOKAHEAD = 128
MUST_BREAK_AFTER =
MUST_NOT_BREAK_AFTER =
MUST_NOT_BREAK_BEFORE =
SEGMENTATION = indexing
SEGMENTATION-all = full
SEGMENTATION-inner = inner
SEGMENTATION-outer = outer
SEGMENTATION-raw = none
SEGMENTATION-standard = standard
SHOULD_LINEMERGE = True
TRANSFORMS =
TRANSFORMS-set = setnull,setparsing
TRUNCATE = 10000
detect_trailing_nulls = auto
maxDist = 100
priority =
sourcetype =
... View more