I've been attempting to route Syslog messages, coming from certain hosts, to a separate index with no success. Below is an example of my config:
Splunk\etc\system\local\
Props.conf
[syslog]
TRANSFORMS-index = test
Transforms.conf
[test]
REGEX = *
FORMAT = myindex
DEST_KEY = _MetaData:Index
"*" is not a valid regex. You need ".*".
Thanks that definitely made a difference 🙂
In inputs.conf
[udp://10.1.1.5:514]
Index=myindex
That also didn't work
Corrections to the Transforms.conf
[test]
REGEX = host=192.168.0.1
FORMAT = myindex
DEST_KEY = _MetaData:Index