Hello everyone I want to add a constant prefix to all my indexes and then forward them this is my props.conf props.conf
[default]
TRANSFORMS-index = rename-index and here is my transforms.conf transforms.conf
[rename-index]
SOURCE_KEY = _MetaData:Index
REGEX = .
FORMAT = foo-$1
DEST_KEY = _MetaData:Index Actually, splunk rename all my indexes to foo-$1 while I want to rename my index to, for example, foo-eventlog, foo-iislog, and so on. any help would be appreciated Thanks in advance
... View more