Splunk Enterprise

How to extract field with variable field

michael_wong
Path Finder

In transforms.conf I can use DELIMS to extract the field by fixed format.

My question is, if one of the field is changeable, how can we resolve that?

Thanks,

Michael

Labels (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @michael_wong,

You can use host based transforms to achieve this. Define new transform setting  And call this transform using host stanza.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

michael_wong
Path Finder

Hi @scelikok,

Thanks for your answer. Can you tell more about how to make priority?

I have made the change, but looks it didn't take effect. If two report defined in transform.conf, which one will take effect?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Here is defined precedences over source, host, sourcetype https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf.

Can you share your configurations, so we can easier help you.

r. Ismo

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Are those in some log file/feed or are they from different source/logs?
0 Karma

michael_wong
Path Finder

No, they are same source, but have a bit difference since configuration inconsistent

0 Karma
Get Updates on the Splunk Community!

Stay Connected: Your Guide to July Tech Talks, Office Hours, and Webinars!

What are Community Office Hours?Community Office Hours is an interactive 60-minute Zoom series where ...

Updated Data Type Articles, Anniversary Celebrations, and More on Splunk Lantern

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

A Prelude to .conf25: Your Guide to Splunk University

Heading to Boston this September for .conf25? Get a jumpstart by arriving a few days early for Splunk ...