diff --git a/deployment-apps/Splunk_TA_linky/local/props.conf b/deployment-apps/Splunk_TA_linky/local/props.conf index bebe8e71..0b695826 100644 --- a/deployment-apps/Splunk_TA_linky/local/props.conf +++ b/deployment-apps/Splunk_TA_linky/local/props.conf @@ -1,4 +1,5 @@ [_json] KV_MODE = json -TRANSFORMS-extract_json = extract_json_fields -TRUNCATE = 0 \ No newline at end of file +SHOULD_LINEMERGE = false +TRUNCATE = 0 +REPORT-extract_fields = extract_fields \ No newline at end of file diff --git a/deployment-apps/Splunk_TA_linky/local/transforms.conf b/deployment-apps/Splunk_TA_linky/local/transforms.conf index 27a84fd6..5b6ad147 100644 --- a/deployment-apps/Splunk_TA_linky/local/transforms.conf +++ b/deployment-apps/Splunk_TA_linky/local/transforms.conf @@ -1,4 +1,4 @@ -[extract_json_fields] -REGEX = \"(?[^\"]+)\":\s?\"(?[^\"]+)\" -FORMAT = $1::$2 +[extract_fields] +REGEX = (?s)(?<=\{).*?(\}) +FORMAT = _json WRITE_META = true \ No newline at end of file