Agreed C. Doing a Ctrl+F within the Splunk reference URL https://docs.splunk.com/Documentation/Splunk/latest/Admin/Transformsconf
REGEX = <regular expression>
* Enter a regular expression to operate on your data.
FORMAT = <string>
* NOTE: This option is valid for both index-time and search-time field extraction. Index-time field extraction configuration require the FORMAT settings. The FORMAT settings is optional for search-time field extraction configurations.
* This setting specifies the format of the event, including any field names or values you want to add.
DEST_KEY = <key>
* NOTE: This setting is only valid for index-time field extractions.
* Specifies where SPLUNK software stores the expanded FORMAT results in accordance with the REGEX match.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
amporiik
Highly Voted 2 years, 4 months agoucsdmiami2020
1 year, 2 months agoApis
Most Recent 11 months, 1 week agoDeltaPotato
1 year, 3 months agoames
2 years, 3 months ago