Knowledge Management

DB-Connect - Extract OK, but need some fields transform [remove spaces]

verbal_666
Builder

Hi guys.
I had a correct DB-Connect connection with a right SELECT with right importing of the table/fields i want.

A problem:

1) raw datas seems to be right, ex,
2019-xx-xx 01:00:00.000, TIPOLOGIA="XXXXX", CATEGORIA="XXXXX", HOSTNAME="XXXXX", SISTEMA OPERATIVO="XXXXX"
... timestamp is right, fields are in the raw data...

2) now the problem... i can search the raw data as well, as said, but Splunk Enterprise 7.0.0, index time, create wrong fields... when found a [SPACE] in field.name ......... so "SISTEMA OPERATIVO" becomes "OPERATIVO", in field cut "SISTEMA[space]".......

3) solution #1: transform field in select " select 'SISTEMA OPERATIVO' as ''SISTEMA_OPERATIVO' ........... "; ok, but i have many fields with this absurd develop (developers should be whipped!!!)

4) solution #2: i can certainly act in indexing time with props/transforms, right? May i use "CLEAN_KEYS" in transforms, with precedente REPORT- in props to do the "trick"? Or something similar?

Thanks.

Tags (1)
0 Karma

verbal_666
Builder

Addon: i also used the "trick" here,

https://answers.splunk.com/answers/417403/how-to-extract-fields-from-splunk-db-connect-2-dat.html

.... and i got it, works search-side, _raw-side.... remain the problem index-side, fields are saved/indexed with wrong field.name.

0 Karma
Get Updates on the Splunk Community!

More Ways To Control Your Costs With Archived Metrics | Register for Tech Talk

Tuesday, May 14, 2024  |  11AM PT / 2PM ET Register to Attend Join us for this Tech Talk and learn how to ...

.conf24 | Personalize your .conf experience with Learning Paths!

Personalize your .conf24 Experience Learning paths allow you to level up your skill sets and dive deeper ...

Threat Hunting Unlocked: How to Uplevel Your Threat Hunting With the PEAK Framework ...

WATCH NOWAs AI starts tackling low level alerts, it's more critical than ever to uplevel your threat hunting ...