Index-time attributes

As discussed in Chapter 3,  Tables, Charts, and Fields under Indexed Fields Versus Extracted Fields section, it is possible to add fields to the metadata of events. This is accomplished by specifying a transform in transforms.conf, and an attribute in props.conf, to tie the transformation to specific events.

The attribute in props.conf looks like this: TRANSFORMS-foo = bar1,bar2.

This attribute references stanzas in transforms.conf by name, in this case, bar1 and bar2. These transform stanzas are then applied to the events matched by the stanza in props.conf.

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.