What is the role of props.conf vs. transforms.conf in field extraction? How do they relate to each other in order to make field extraction work?
asked 15 Jan '10, 18:21
The high-level answer is that props.conf says what rules are applied to any event and when they are applied, and transforms.conf actually defines those rules.
So in props.conf, you say "events with the sourcetype XXX has the extraction YYY applied to it at parse time" or "events from host HHH has lookup JJJ applied at search time". transforms.conf would specify exactly how extraction XXX worked, or where lookup JJJ comes from.
This is generally true, though it's a little muddied because some of the rules are specified directly in props.conf. Some of these (e.g., rules for parsing timestamps or line breaks) are only specified in props.conf, while others (search time field extractions) can be either directly defined in props.conf, or referenced back to transforms.conf
answered 15 Jan '10, 19:10
regex based field extraction can be specified:
answered 15 Jan '10, 20:02
Ledion Bitincka ♦