Splunk Search

field transformation not cpaturing anything

aviadr1
Explorer

I am trying the field tranformation feature. using the "Manager » Fields » Field transformations" UI
I have defined the following transformation
regex=(?.)
key=_raw
format=

now I'm searching for aviad=* in search app and no event comes up. what gives?

Tags (3)
0 Karma

woodcock
Esteemed Legend

You did not provide any field naming/mapping; try this:

regex=(?.) key=_raw format=aviad::$1
0 Karma
Get Updates on the Splunk Community!

Introducing Splunk Enterprise 9.2

WATCH HERE! Watch this Tech Talk to learn about the latest features and enhancements shipped in the new Splunk ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...

Routing logs with Splunk OTel Collector for Kubernetes

The Splunk Distribution of the OpenTelemetry (OTel) Collector is a product that provides a way to ingest ...