Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

Why is the data not being filtered to another index?

$
0
0
I have the following configuration for filtering the data coming from X udp port data input to an index that's being already created: props.conf [source::udp:X] TRANSFORMS-new_index= route_index transforms.conf [route_index] REGEX = ^"ip_add"$ DEST_KEY = _MetaData:Index FORMAT = new_index I know I'm almost there, but why it isn't working how it is supposed to? Thanks!

Viewing all articles
Browse latest Browse all 47296

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>