diff --git a/deployment-apps/Splunk_TA_linky/local/props.conf b/deployment-apps/Splunk_TA_linky/local/props.conf index 0b695826..bebe8e71 100644 --- a/deployment-apps/Splunk_TA_linky/local/props.conf +++ b/deployment-apps/Splunk_TA_linky/local/props.conf @@ -1,5 +1,4 @@ [_json] KV_MODE = json -SHOULD_LINEMERGE = false -TRUNCATE = 0 -REPORT-extract_fields = extract_fields \ No newline at end of file +TRANSFORMS-extract_json = extract_json_fields +TRUNCATE = 0 \ No newline at end of file diff --git a/deployment-apps/Splunk_TA_linky/local/transforms.conf b/deployment-apps/Splunk_TA_linky/local/transforms.conf index 5b6ad147..27a84fd6 100644 --- a/deployment-apps/Splunk_TA_linky/local/transforms.conf +++ b/deployment-apps/Splunk_TA_linky/local/transforms.conf @@ -1,4 +1,4 @@ -[extract_fields] -REGEX = (?s)(?<=\{).*?(\}) -FORMAT = _json +[extract_json_fields] +REGEX = \"(?[^\"]+)\":\s?\"(?[^\"]+)\" +FORMAT = $1::$2 WRITE_META = true \ No newline at end of file