This question may seem pretty silly but I'm really clueless about SPLUNK.
I do know where to configure the props.conf,however,I'm not too sure how do I configure the transform.conf for my logs. How do I go about doing it?
Do I put the transform.conf into the field where I input my props.conf as well? (At the start when I'm importing my data into SPLUNK)
Please help me!
asked 15 May '12, 01:56
Not sure exactly what you are asking. Transforms.conf would be located in the same folder as props.conf. I would suggest looking at some other answers on here to find one that matches what you are trying to accomplish.
You are probably looking to do one of the following:
If your props.conf is looking sometyhing like
"some props.conf entries e.g KV_MODE,SEDCMD"
REPORT-report = unclean
then it will reference the stanza "unclean" in transforms.conf
your transforms.conf would look like
CLEAN_KEYS = 0
DELIMS = "(""|", "="
Hope that clears things up for you
answered 15 May '12, 06:00