Hello. Props.conf is not applying on my universal forwarder. I diagnosed with btool and it seems that the setting are being applied yet when the data gets shipped to my server, it is in raw form.
inputs.conf:
[batch://C:\Data\*\Cloud-Data\to_splunk\(...)?(?i)*_CloudTrail_*]
sourcetype = aws-cloudtrail
move_policy = sinkhole
index = testindex
Props.conf:
[aws-cloudtrail]
LINE_BREAKER=((?<=}),(?={"eventVersion"))
NO_BINARY_CHECK=true
CHARSET=UTF-8
KV_MODE=json
SEDCMD-remove_prefix=s/{"Records":\[//g
SEDCMD-remove_suffix=s/\]}//g
TIME_PREFIX=eventTime
TRANSFORMS-index = write-index
transforms.conf
[write-index]
SOURCE_KEY = MetaData:Source
DEST_KEY = _MetaData:Index
REGEX = .*\\Data\\+(?<yeet>.*)\\.*\\to_splunk.*
FORMAT = $1
... View more