<?xml version="1.0" ?>
<rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
	<channel>
		<title>Splunk Base : SplunkAdministration : #2797</title>
		<link>http://www.splunk.com/support/forum:SplunkAdministration/2797</link>
		<description></description>
		<pubDate>Mon, 13 Feb 2012 18:19:02 PST</pubDate>
		<lastBuildDate>Mon, 13 Feb 2012 18:19:02 PST</lastBuildDate>
		<language>en-us</language>
		<copyright>http://creativecommons.org/licenses/by-nc-nd/2.5/</copyright>
		<item>
			<title>Move WMI Input to different Indexes</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/2797/9053</link>
			<description>&lt;p&gt;I'm not sure about your regex. what exactly are you trying match on?&lt;/p&gt;

</description>
			<pubDate>Fri, 05 Jun 2009 23:28:29 PDT</pubDate>
			<author>gkanapathy</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/2797/9053</guid>
		</item>
		<item>
			<title>Move WMI Input to different Indexes</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/2797/8962</link>
			<description>&lt;p&gt;I have read a post that wmi remote events have a specific behaviour at transformation time&lt;/p&gt;

&lt;p&gt;Now I have configured my props.conf&lt;br /&gt;
[wmi]&lt;br /&gt;
TRANSFORMS-index = &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/WinSec&quot;&gt;WinSec&lt;/a&gt;_Maschine1&lt;/p&gt;

&lt;p&gt;and my transforms.conf&lt;br /&gt;
[&lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/WinSec&quot;&gt;WinSec&lt;/a&gt;_Maschine1]&lt;br /&gt;
REGEX = &lt;a class=&quot;wiki_url_new&quot; href=&quot;/base/ComputerName&quot;&gt;ComputerName&lt;/a&gt;[=]Maschine1&lt;br /&gt;
DEST_KEY = _MetaData:Index&lt;br /&gt;
FORMAT = index_project1&lt;/p&gt;

&lt;p&gt;but this don't work. I have tried a few regex combinations without success&lt;br /&gt;
Do you see any failure ?&lt;/p&gt;

&lt;p&gt;Thanks &lt;br /&gt;
Rob&lt;/p&gt;

</description>
			<pubDate>Tue, 26 May 2009 04:40:53 PDT</pubDate>
			<author>RobertRi</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/2797/8962</guid>
		</item>
		<item>
			<title>Move WMI Input to different Indexes</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/2797/8960</link>
			<description>&lt;p&gt;I would split systems wich refers to a specific project&lt;br /&gt;
That I  have one Index with logs from application, OS sytem and others which belongs to a specific product&lt;/p&gt;

</description>
			<pubDate>Tue, 26 May 2009 01:57:56 PDT</pubDate>
			<author>RobertRi</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/2797/8960</guid>
		</item>
		<item>
			<title>Move WMI Input to different Indexes</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/2797/8958</link>
			<description>&lt;p&gt;Can you explain why you want to split different hosts into different indexes?&lt;/p&gt;

</description>
			<pubDate>Mon, 25 May 2009 17:53:24 PDT</pubDate>
			<author>gkanapathy</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/2797/8958</guid>
		</item>
		<item>
			<title>Move WMI Input to different Indexes</title>
			<link>http://www.splunk.com/support/forum:SplunkAdministration/2797/8957</link>
			<description>&lt;p&gt;Hello&lt;/p&gt;

&lt;p&gt;I have a problem with Splunk 3.4.3 on Windows and remote wmi.&lt;br /&gt;
Here I will index the application log&lt;br /&gt;
I would like to split, different hosts in different indexes but in wmi.conf, I have no option to configure index=xyz.&lt;/p&gt;

&lt;p&gt;My first idea is to work with props and transforms.conf on the indexing server site and point a regex on computername=mycomputer and move this messages to a different index&lt;/p&gt;

&lt;p&gt;Maybe anyone has a better solution for my problem ?&lt;/p&gt;

&lt;p&gt;Thanks&lt;br /&gt;
Rob&lt;/p&gt;

</description>
			<pubDate>Mon, 25 May 2009 06:15:26 PDT</pubDate>
			<author>RobertRi</author>
			<guid>http://www.splunk.com/support/forum:SplunkAdministration/2797/8957</guid>
		</item>
	</channel>
</rss>

