<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Forward only WARN OR ERROR log lines to splunk in Security</title>
    <link>https://community.splunk.com/t5/Security/Forward-only-WARN-OR-ERROR-log-lines-to-splunk/m-p/497031#M15376</link>
    <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;Need your expert advise on how can I configure my logstash.conf file to forward only the ERROR OR WARN log lines to Splunk. I have done some online research that a grok filter or wrapping the output with if condition can be used in order the acheive the required result.&lt;/P&gt;

&lt;P&gt;I would appreciate if you could share a working example on the same. Many thanks!&lt;/P&gt;</description>
    <pubDate>Wed, 13 May 2020 21:12:25 GMT</pubDate>
    <dc:creator>vivek991985</dc:creator>
    <dc:date>2020-05-13T21:12:25Z</dc:date>
    <item>
      <title>Forward only WARN OR ERROR log lines to splunk</title>
      <link>https://community.splunk.com/t5/Security/Forward-only-WARN-OR-ERROR-log-lines-to-splunk/m-p/497031#M15376</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;

&lt;P&gt;Need your expert advise on how can I configure my logstash.conf file to forward only the ERROR OR WARN log lines to Splunk. I have done some online research that a grok filter or wrapping the output with if condition can be used in order the acheive the required result.&lt;/P&gt;

&lt;P&gt;I would appreciate if you could share a working example on the same. Many thanks!&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 21:12:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forward-only-WARN-OR-ERROR-log-lines-to-splunk/m-p/497031#M15376</guid>
      <dc:creator>vivek991985</dc:creator>
      <dc:date>2020-05-13T21:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: Forward only WARN OR ERROR log lines to splunk</title>
      <link>https://community.splunk.com/t5/Security/Forward-only-WARN-OR-ERROR-log-lines-to-splunk/m-p/497032#M15377</link>
      <description>&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/59370/filtering-events-using-nullqueue-1.html"&gt;https://answers.splunk.com/answers/59370/filtering-events-using-nullqueue-1.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Can't you just delete it on the Splunk side?&lt;/P&gt;</description>
      <pubDate>Wed, 13 May 2020 23:52:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forward-only-WARN-OR-ERROR-log-lines-to-splunk/m-p/497032#M15377</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-05-13T23:52:11Z</dc:date>
    </item>
    <item>
      <title>Re: Forward only WARN OR ERROR log lines to splunk</title>
      <link>https://community.splunk.com/t5/Security/Forward-only-WARN-OR-ERROR-log-lines-to-splunk/m-p/497033#M15378</link>
      <description>&lt;P&gt;I do not want to delete it at Splunk side.&lt;/P&gt;

&lt;P&gt;I prefer not to send the data with INFO OR DEBUG logging levels to Splunk, therefore, looking forward to getting some clean solution to implement it.&lt;/P&gt;

&lt;P&gt;Please advise how logstash.conf should be updated to achieve the required result.&lt;/P&gt;

&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 05:42:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forward-only-WARN-OR-ERROR-log-lines-to-splunk/m-p/497033#M15378</guid>
      <dc:creator>vivek991985</dc:creator>
      <dc:date>2020-05-14T05:42:38Z</dc:date>
    </item>
    <item>
      <title>Re: Forward only WARN OR ERROR log lines to splunk</title>
      <link>https://community.splunk.com/t5/Security/Forward-only-WARN-OR-ERROR-log-lines-to-splunk/m-p/497034#M15379</link>
      <description>&lt;P&gt;Hi @vivek991985,&lt;BR /&gt;
the logging level doesn't depend on Splunk, it depends on the source, so maybe you should ask to a logstash forum.&lt;/P&gt;

&lt;P&gt;Anyway, you can filter in Splunk the not interesting logs following the steps described at &lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.3/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.3/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues&lt;/A&gt; .&lt;/P&gt;

&lt;P&gt;Ciao.&lt;BR /&gt;
Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 06:17:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forward-only-WARN-OR-ERROR-log-lines-to-splunk/m-p/497034#M15379</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-05-14T06:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: Forward only WARN OR ERROR log lines to splunk</title>
      <link>https://community.splunk.com/t5/Security/Forward-only-WARN-OR-ERROR-log-lines-to-splunk/m-p/497035#M15380</link>
      <description>&lt;P&gt;Thanks very much Giuseppe for your help! Noted.&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 06:20:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Security/Forward-only-WARN-OR-ERROR-log-lines-to-splunk/m-p/497035#M15380</guid>
      <dc:creator>vivek991985</dc:creator>
      <dc:date>2020-05-14T06:20:08Z</dc:date>
    </item>
  </channel>
</rss>

