transforms.conf

The transforms.conf configuration is where we specify transformations and lookups that can then be applied to any event. These transforms and lookups are referenced by name in props.conf.

For our examples in the later subsections, we will use this event:

2012-09-24T00:21:35.925+0000 DEBUG [MBX] Password reset called. 
[old=1234, new=secret, req_time=5346] 

We will use it with these metadata values:

sourcetype=myapp 
source=/logs/myapp.session_foo-jA5MDkyMjEwMTIK.log 
host=vlbmba.local 

Get Implementing Splunk 7 - Third Edition now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.