<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Limiting ingested fields in Azure Event Hubs in All Apps and Add-ons</title>
    <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Limiting-ingested-fields-in-Azure-Event-Hubs/m-p/513444#M62895</link>
    <description>&lt;P&gt;Thanks for the info.&amp;nbsp; &amp;nbsp;can i discard or manipulate fields in an event.&amp;nbsp; &amp;nbsp;I'm going to speak logstash here and mutate to delete "reallybigfieldIdon'tcareabout"&lt;/P&gt;</description>
    <pubDate>Mon, 10 Aug 2020 20:47:29 GMT</pubDate>
    <dc:creator>zippo706</dc:creator>
    <dc:date>2020-08-10T20:47:29Z</dc:date>
    <item>
      <title>Limiting ingested fields in Azure Event Hubs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Limiting-ingested-fields-in-Azure-Event-Hubs/m-p/513421#M62892</link>
      <description>&lt;P&gt;I"d like to send audit data through an event hub.&amp;nbsp; &amp;nbsp;However, i want my heavy fwd'r to not send all fields to splunk as 75% of is will be useless and take up all my ingesting quota.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there an easy way to do this?&amp;nbsp; The data coming in is Azure SQL where i don't beleive i can change data going into the hub.&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 19:38:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Limiting-ingested-fields-in-Azure-Event-Hubs/m-p/513421#M62892</guid>
      <dc:creator>zippo706</dc:creator>
      <dc:date>2020-08-10T19:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting ingested fields in Azure Event Hubs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Limiting-ingested-fields-in-Azure-Event-Hubs/m-p/513440#M62894</link>
      <description>&lt;P&gt;If you want to discard entire events, see&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.5/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.5/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues&lt;/A&gt;&lt;/P&gt;&lt;P&gt;If you want to discard parts of events, use SEDCMD in props.conf.&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[mysourcetype]
SEDCMD-winevent = s/This event is generated.*//&lt;/LI-CODE&gt;</description>
      <pubDate>Mon, 10 Aug 2020 20:38:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Limiting-ingested-fields-in-Azure-Event-Hubs/m-p/513440#M62894</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-10T20:38:57Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting ingested fields in Azure Event Hubs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Limiting-ingested-fields-in-Azure-Event-Hubs/m-p/513444#M62895</link>
      <description>&lt;P&gt;Thanks for the info.&amp;nbsp; &amp;nbsp;can i discard or manipulate fields in an event.&amp;nbsp; &amp;nbsp;I'm going to speak logstash here and mutate to delete "reallybigfieldIdon'tcareabout"&lt;/P&gt;</description>
      <pubDate>Mon, 10 Aug 2020 20:47:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Limiting-ingested-fields-in-Azure-Event-Hubs/m-p/513444#M62895</guid>
      <dc:creator>zippo706</dc:creator>
      <dc:date>2020-08-10T20:47:29Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting ingested fields in Azure Event Hubs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Limiting-ingested-fields-in-Azure-Event-Hubs/m-p/513471#M62898</link>
      <description>Yes, you can do that with SEDCMD. It will be on the raw event, however, since fields haven't been extracted when SEDCMD runs.</description>
      <pubDate>Tue, 11 Aug 2020 00:29:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Limiting-ingested-fields-in-Azure-Event-Hubs/m-p/513471#M62898</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2020-08-11T00:29:08Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting ingested fields in Azure Event Hubs</title>
      <link>https://community.splunk.com/t5/All-Apps-and-Add-ons/Limiting-ingested-fields-in-Azure-Event-Hubs/m-p/513744#M62914</link>
      <description>&lt;P&gt;Thank you, much appreciated.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2020 16:02:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/All-Apps-and-Add-ons/Limiting-ingested-fields-in-Azure-Event-Hubs/m-p/513744#M62914</guid>
      <dc:creator>zippo706</dc:creator>
      <dc:date>2020-08-12T16:02:27Z</dc:date>
    </item>
  </channel>
</rss>

