Splunk Search

Can we use conditional statements in transforms.conf ?

ranjyotiprakash
Communicator

Can we use conditional statements in transforms.conf in case we are having different formats for the logs??
Or if we are having different log formats, is there a way to implement this in my app?

Thankssss !!

Tags (2)
0 Karma

sdaniels
Splunk Employee
Splunk Employee

Not completely clear on what you want to do. You could configure rule based sourcetyping to manage various formats.

http://docs.splunk.com/Documentation/Splunk/4.3.2/Data/Configurerule-basedsourcetyperecognition

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...