Getting Data In

Is an entry in props.conf required to allow an entry in transforms.conf to be effective?

msantich
Path Finder

When the following question was asked in this forum:
What is the role of transforms.conf vs. props.conf for field extraction?

The answer was:

The high-level answer is that props.conf says what rules are applied to any event and when they are applied, and transforms.conf actually defines those rules.

but is the entry in props.conf REQUIRED to map to an entry in transforms.conf so that the rule is applied?

thank you

0 Karma
1 Solution

somesoni2
Revered Legend

Yes. Props.conf define the entity (host/source/sourcetype) to which rules will be applied and provides a pointer to a transforms.conf entry which actually defines the rule.

View solution in original post

0 Karma

somesoni2
Revered Legend

Yes. Props.conf define the entity (host/source/sourcetype) to which rules will be applied and provides a pointer to a transforms.conf entry which actually defines the rule.

0 Karma

msantich
Path Finder

very nice...thank you for the quick answer.

0 Karma

ppablo
Retired

Hi @msantich

Please be sure to resolve the question by clicking "Accept" directly below @somesoni2's answer. Don't forget to do this for all of your posts with answers that solve your issues.

0 Karma
Get Updates on the Splunk Community!

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...

Splunk APM: New Product Features + Community Office Hours Recap!

Howdy Splunk Community! Over the past few months, we’ve had a lot going on in the world of Splunk Application ...

Index This | Forward, I’m heavy; backward, I’m not. What am I?

April 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...