Quantcast
Channel: Latest Questions on Splunk Answers
Viewing all articles
Browse latest Browse all 13053

Route Syslogs coming from certain hosts into a separate index

$
0
0

I've been attempting to route Syslog messages, coming from certain hosts, to a separate index with no success. Below is an example of my config:

Splunketcsystemlocal\

Props.conf [syslog] TRANSFORMS-index = test

Transforms.conf [test] REGEX = * FORMAT = myindex DEST_KEY = _MetaData:Index


Viewing all articles
Browse latest Browse all 13053

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>