diff --git a/package/default/props.conf b/package/default/props.conf index 13c5871..fc4c8fb 100644 --- a/package/default/props.conf +++ b/package/default/props.conf @@ -14,4 +14,17 @@ ANNOTATE_PUNCT = false DATETIME_CONFIG=CURRENT -REPORT-fields = ta_sc4snmp_trap \ No newline at end of file +REPORT-fields = ta_sc4snmp_kv + +[sc4snmp:meta] +pulldown_type = 0 +NO_BINARY_CHECK = 1 +SHOULD_LINEMERGE = false +KV_MODE = NONE +LEARN_SOURCETYPE = false +LEARN_MODEL = false +ANNOTATE_PUNCT = false + +DATETIME_CONFIG=CURRENT + +REPORT-fields = ta_sc4snmp_kv diff --git a/package/default/transforms.conf b/package/default/transforms.conf index d0825b2..413f8ec 100644 --- a/package/default/transforms.conf +++ b/package/default/transforms.conf @@ -3,5 +3,5 @@ ## SPDX-License-Identifier: LicenseRef-Splunk-1-2020 ## ## -[ta_sc4snmp_trap] +[ta_sc4snmp_kv] REGEX = (?:^| )(?<_KEY_1>[^=]*)=(?! )(?<_VAL_1>.+?)(?=(?: [^ ]*(?