Splunk Enterprise

How to extract field with variable field

michael_wong
Path Finder

In transforms.conf I can use DELIMS to extract the field by fixed format.

My question is, if one of the field is changeable, how can we resolve that?

Thanks,

Michael

Labels (1)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @michael_wong,

You can use host based transforms to achieve this. Define new transform setting  And call this transform using host stanza.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

michael_wong
Path Finder

Hi @scelikok,

Thanks for your answer. Can you tell more about how to make priority?

I have made the change, but looks it didn't take effect. If two report defined in transform.conf, which one will take effect?

0 Karma

isoutamo
SplunkTrust
SplunkTrust

Here is defined precedences over source, host, sourcetype https://docs.splunk.com/Documentation/Splunk/latest/Admin/Propsconf.

Can you share your configurations, so we can easier help you.

r. Ismo

0 Karma

isoutamo
SplunkTrust
SplunkTrust
Are those in some log file/feed or are they from different source/logs?
0 Karma

michael_wong
Path Finder

No, they are same source, but have a bit difference since configuration inconsistent

0 Karma
Get Updates on the Splunk Community!

Expert Tips from Splunk Professional Services, Ensuring Compliance, and More New ...

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...

Observability Release Update: AI Assistant, AppD + Observability Cloud Integrations & ...

This month’s releases across the Splunk Observability portfolio deliver earlier detection and faster ...

Stay Connected: Your Guide to February Tech Talks, Office Hours, and Webinars!

💌Keep the new year’s momentum going with our February lineup of Community Office Hours, Tech Talks, ...