<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help filtering data to nullQueue in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Help-filtering-data-to-nullQueue/m-p/530232#M4215</link>
    <description>&lt;P&gt;I'm an idiot.&amp;nbsp; It's transforms.conf, not transform.conf.&lt;BR /&gt;Fixing.....&lt;/P&gt;</description>
    <pubDate>Fri, 20 Nov 2020 15:47:13 GMT</pubDate>
    <dc:creator>aaronbarrett</dc:creator>
    <dc:date>2020-11-20T15:47:13Z</dc:date>
    <item>
      <title>Help filtering data to nullQueue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Help-filtering-data-to-nullQueue/m-p/530231#M4214</link>
      <description>&lt;P&gt;Good day,&lt;/P&gt;&lt;P&gt;This is my first time trying to filter data with props.conf/transform.conf.&amp;nbsp; Sorry if this post is in the wrong location.&lt;/P&gt;&lt;P&gt;This is on a standalone Windows Splunk 8.0.3 box.&lt;/P&gt;&lt;P&gt;I have placed the props.conf/transform.conf in the C:\Program Files\Splunk\etc\system\local directory.&lt;/P&gt;&lt;P&gt;The data I want to filter out is the Rhttpproxy data from an ESXi host.&lt;/P&gt;&lt;P&gt;&amp;lt;167&amp;gt;2020-11-20T15:12:26.668Z ESX01.test.com Rhttpproxy: verbose rhttpproxy[2101380] [Originator@6876 sub=Proxy Req 11290] Resolved endpoint : [N7Vmacore4Http16LocalServiceSpecE:0x0000005839540e50] _serverNamespace = /vpxa action = Allow _port = 8089&lt;/P&gt;&lt;P&gt;host = 192.168.10.10&lt;BR /&gt;process = Rhttpproxy&lt;BR /&gt;source = tcp:514&lt;BR /&gt;sourcetype = syslog&lt;BR /&gt;===========================&lt;BR /&gt;My current config is:&lt;/P&gt;&lt;P&gt;props.conf&lt;BR /&gt;[source::tcp:514]&lt;BR /&gt;TRANSFORMS-null = setnull&lt;/P&gt;&lt;P&gt;transform.conf&lt;BR /&gt;[setnull]&lt;BR /&gt;REGEX = rhttpproxy&lt;BR /&gt;DEST_KEY = queue&lt;BR /&gt;FORMAT = nullQueue&lt;BR /&gt;================================&lt;BR /&gt;Things I have tried&lt;BR /&gt;--&lt;BR /&gt;[host::192.168.10.10]&lt;BR /&gt;TRANSFORMS-null = setnull&lt;BR /&gt;--&lt;BR /&gt;[host::192\.168\.10\.10]&lt;BR /&gt;TRANSFORMS-null = setnull&lt;BR /&gt;--&lt;BR /&gt;[syslog]&lt;BR /&gt;TRANSFORMS-null = setnull&lt;BR /&gt;--&lt;BR /&gt;[setnull]&lt;BR /&gt;REGEX = verbose\srhttpproxy&lt;BR /&gt;DEST_KEY = queue&lt;BR /&gt;FORMAT = nullQueue&lt;BR /&gt;--&lt;BR /&gt;[setnull]&lt;BR /&gt;SOURCE_KEY = field:process&lt;BR /&gt;REGEX = Rhttpproxy&lt;BR /&gt;DEST_KEY = queue&lt;BR /&gt;FORMAT = nullQueue&lt;BR /&gt;--&lt;BR /&gt;&lt;BR /&gt;I have read the documentation several times, and I am not just understanding it.&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.3/Admin/Transformsconf" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.0/Admin/Transformsconf&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.0.3/Admin/Propsconf" target="_blank" rel="noopener"&gt;https://docs.splunk.com/Documentation/Splunk/8.0.3/Admin/Propsconf&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;BR /&gt;Aaron&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 15:38:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Help-filtering-data-to-nullQueue/m-p/530231#M4214</guid>
      <dc:creator>aaronbarrett</dc:creator>
      <dc:date>2020-11-20T15:38:16Z</dc:date>
    </item>
    <item>
      <title>Re: Help filtering data to nullQueue</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Help-filtering-data-to-nullQueue/m-p/530232#M4215</link>
      <description>&lt;P&gt;I'm an idiot.&amp;nbsp; It's transforms.conf, not transform.conf.&lt;BR /&gt;Fixing.....&lt;/P&gt;</description>
      <pubDate>Fri, 20 Nov 2020 15:47:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Help-filtering-data-to-nullQueue/m-p/530232#M4215</guid>
      <dc:creator>aaronbarrett</dc:creator>
      <dc:date>2020-11-20T15:47:13Z</dc:date>
    </item>
  </channel>
</rss>

