Hi @PickleRick, Thank you for your suggestions.      After following your suggestions, the configurations are now working correctly for my use case. Here are the changes I made for [route_to_teamid_index] stanza in transforms.conf:    1) For [route_to_teamid_index]  - Set FORMAT = $1  - Updated SOURCE_KEY = MetaData:Source    Current working configs for my use cases:  -----------------------------------------------------------------------------  props  -----------------------------------------------------------------------------  #custom-props-for-starflow-logs  [source::.../starflow-app-logs...]  TRANSFORMS-set_new_sourcetype = new_sourcetype  TRANSFORMS-set_route_to_teamid_index = route_to_teamid_index    -----------------------------------------------------------------------------  transforms  -----------------------------------------------------------------------------  #custom-transforms-for-starflow-logs  [new_sourcetype]  REGEX = .*  DEST_KEY = MetaData:Sourcetype  FORMAT = sourcetype::aws:kinesis:starflow  WRITE_META = true    [route_to_teamid_index]  REGEX = .*\/starflow-app-logs(?:-[a-z]+)?\/([a-zA-Z0-9]+)\/  SOURCE_KEY = MetaData:Source  FORMAT = $1  DEST_KEY = _MetaData:Index  WRITE_META = true  Previously, the configuration had SOURCE_KEY = source, which was causing issues. The SOURCE_KEY = <field> setting essentially tells Splunk where the regex should be applied. In my configuration, it was set to "source" but Splunk might not have been able to apply the regex to just the source field. After spending time reading through transforms.conf, I noticed that under the global settings, there was a specific mention of this.  SOURCE_KEY = <string>
* NOTE: This setting is valid for both index-time and search-time field
  extractions.
* Optional. Defines the KEY that Splunk software applies the REGEX to.
* For search time extractions, you can use this setting to extract one or
  more values from the values of another field. You can use any field that
  is available at the time of the execution of this field extraction
* For index-time extractions use the KEYs described at the bottom of this
  file.
  * KEYs are case-sensitive, and should be used exactly as they appear in
    the KEYs list at the bottom of this file. (For example, you would say
    SOURCE_KEY = MetaData:Host, *not* SOURCE_KEY = metadata:host .)    Keys   MetaData:Source     : The source associated with the event.      Thank you sincerely for all of your genuine help! 
						
					
					... View more