Quantcast
Channel: Questions in topic: "splunk-enterprise"
Viewing all articles
Browse latest Browse all 47296

MATCH_LIMIT in tranforms.conf

$
0
0
I have a fairly hefty chunk of JSON from RabbitMQ REST. In my props I have: [json_no_timestamp] TRUNCATE = 500000 In transforms, I have: [CFBPFCCmessages] REGEX = (?U)()"messages":(?P\d+) WRITE_META = true FORMAT = CFBPFCCmessages::$2 [CFBPFfailed] REGEX = (?U)()"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFBPFfailed::$2 [CFBPFmobile] REGEX = (?U)()"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFBPFmobile::$2 [CFBPFonboard] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFBPFonboard::$2 [CFBPFticketoffice] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFBPFticketoffice::$2 [CFBPFtvm] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFBPFtvm::$2 [CFBPFunknown] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFBPFunknown::$2 [CFBPFweb] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFBPFweb::$2 [CFBPMemail] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFBPMemail::$2 [CFBPMfailed] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFBPMfailed::$2 [CFBPMsms] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFBPMsms::$2 [CFBPMunknown] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFBPMunknown::$2 [CFGPFCCmessages] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+) WRITE_META = true FORMAT = CFGPFCCmessages::$2 [CFGPFfailed] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFGPFfailed::$2 [CFGPFmobile] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFGPFmobile::$2 [CFGPFonboard] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFGPFonboard::$2 [CFGPFticketoffice] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFGPFticketoffice::$2 [CFGPFtvm] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFGPFtvm::$2 [CFGPFunknown] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFGPFunknown::$2 [CFGPFweb] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFGPFweb::$2 [CFGPMemail] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFGPMemail::$2 [CFGPMfailed] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFGPMfailed::$2 [CFGPMsms] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFGPMsms::$2 [CFGPMunknown] REGEX = (?U)()"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":.+"messages":(?P\d+),"messages WRITE_META = true FORMAT = CFGPMunknown::$2 When indexing, I only get the first 3 fields, the other fields beyond **CFBPFmobile** are not indexed. I was considering MATCH_LIMIT, will this work?

Viewing all articles
Browse latest Browse all 47296

Latest Images

Trending Articles



Latest Images

<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>