<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Sending data to nullqueue using props and transafoms is not working. in Splunk Enterprise</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-nullqueue-using-props-and-transafoms-is-not/m-p/325369#M6650</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I am trying to send data to nullqueue so that events will not get indexed. we can save license consumption.&lt;/P&gt;

&lt;P&gt;Props.conf&lt;/P&gt;

&lt;P&gt;[testfiltering]&lt;BR /&gt;
DATETIME_CONFIG = &lt;BR /&gt;
NO_BINARY_CHECK = true&lt;BR /&gt;
category = Custom&lt;BR /&gt;
disabled = false&lt;BR /&gt;
pulldown_type = true&lt;BR /&gt;
TRANSFORMS-SERVICE = eventsDrop&lt;/P&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;P&gt;[eventsDrop]&lt;BR /&gt;
REGEX = (?m)^THREAD.&lt;EM&gt;SERVICE-.*E2ELoggingSupport.&lt;/EM&gt;&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = nullQueue&lt;/P&gt;

&lt;P&gt;Log details to be filtered &lt;BR /&gt;
2017-07-05 15:54:30.157 INFO  THREAD-1321 SERVICE-[MDP Feeder]_BusinessFlowSelectorService_H075F54304221O1P H075F54304321O1Q E2ELoggingSupport        : Payment Id: H075F54304321O1Q, JMS msg received header [Destination=queue:///GPP.FROMDP.SEND.PAYMNT.INSTRCTN.IN,DeliveryMode=2,Expiration=0 null,Priority=4,MessageID=ID:414d51204445564750503032202020205959ceef1000b103,Timestamp=1499233913142 2017-07-05T15:51:53.142,CorrelationID=null,ReplyTo=null,Redelivered=false,Type=null] PropertyNames=[JMS_IBM_Format=MQSTR   ][JMS_IBM_Character_Set=UTF-8][JMSXDeliveryCount=1][JMS_IBM_Encoding=273][JMSXUserID=pegapsup    ][JMS_IBM_MsgType=8][JMS_IBM_PutApplType=28][JMS_IBM_PutDate=20170705][JMS_IBM_PutTime=05512391][JMSXAppID=hermes.browser.HermesBrowser]&lt;/P&gt;

&lt;P&gt;Thanks/Sagar&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 15:01:36 GMT</pubDate>
    <dc:creator>SagarSplunk</dc:creator>
    <dc:date>2020-09-29T15:01:36Z</dc:date>
    <item>
      <title>Sending data to nullqueue using props and transafoms is not working.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-nullqueue-using-props-and-transafoms-is-not/m-p/325369#M6650</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;

&lt;P&gt;I am trying to send data to nullqueue so that events will not get indexed. we can save license consumption.&lt;/P&gt;

&lt;P&gt;Props.conf&lt;/P&gt;

&lt;P&gt;[testfiltering]&lt;BR /&gt;
DATETIME_CONFIG = &lt;BR /&gt;
NO_BINARY_CHECK = true&lt;BR /&gt;
category = Custom&lt;BR /&gt;
disabled = false&lt;BR /&gt;
pulldown_type = true&lt;BR /&gt;
TRANSFORMS-SERVICE = eventsDrop&lt;/P&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;P&gt;[eventsDrop]&lt;BR /&gt;
REGEX = (?m)^THREAD.&lt;EM&gt;SERVICE-.*E2ELoggingSupport.&lt;/EM&gt;&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = nullQueue&lt;/P&gt;

&lt;P&gt;Log details to be filtered &lt;BR /&gt;
2017-07-05 15:54:30.157 INFO  THREAD-1321 SERVICE-[MDP Feeder]_BusinessFlowSelectorService_H075F54304221O1P H075F54304321O1Q E2ELoggingSupport        : Payment Id: H075F54304321O1Q, JMS msg received header [Destination=queue:///GPP.FROMDP.SEND.PAYMNT.INSTRCTN.IN,DeliveryMode=2,Expiration=0 null,Priority=4,MessageID=ID:414d51204445564750503032202020205959ceef1000b103,Timestamp=1499233913142 2017-07-05T15:51:53.142,CorrelationID=null,ReplyTo=null,Redelivered=false,Type=null] PropertyNames=[JMS_IBM_Format=MQSTR   ][JMS_IBM_Character_Set=UTF-8][JMSXDeliveryCount=1][JMS_IBM_Encoding=273][JMSXUserID=pegapsup    ][JMS_IBM_MsgType=8][JMS_IBM_PutApplType=28][JMS_IBM_PutDate=20170705][JMS_IBM_PutTime=05512391][JMSXAppID=hermes.browser.HermesBrowser]&lt;/P&gt;

&lt;P&gt;Thanks/Sagar&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:01:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-nullqueue-using-props-and-transafoms-is-not/m-p/325369#M6650</guid>
      <dc:creator>SagarSplunk</dc:creator>
      <dc:date>2020-09-29T15:01:36Z</dc:date>
    </item>
    <item>
      <title>Re: Sending data to nullqueue using props and transafoms is not working.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-nullqueue-using-props-and-transafoms-is-not/m-p/325370#M6651</link>
      <description>&lt;P&gt;Your RegEx anchors "THREAD" to the beginning of the line, but it doesn't show up at the beginning of the line. Either add the patterns for timestamp and category to your RegEx or remove the caret (^).&lt;/P&gt;

&lt;P&gt;Also, make sure you put those configs where the parsing occurs; probably your indexers.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Jul 2017 21:31:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-nullqueue-using-props-and-transafoms-is-not/m-p/325370#M6651</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-07-20T21:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: Sending data to nullqueue using props and transafoms is not working.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-nullqueue-using-props-and-transafoms-is-not/m-p/325371#M6652</link>
      <description>&lt;P&gt;HI SSievert,&lt;BR /&gt;
Now I changed my configurations  as below but still I am unable to filter out the above events. am I missing something? syntax is correct for regex? I trying to filter out events before it index&lt;/P&gt;

&lt;P&gt;[eventsDrop]&lt;BR /&gt;
REGEX = SERVICE-.E2ELoggingSupport.&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = nullQueue&lt;/P&gt;

&lt;P&gt;Thanks/Sagar&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jul 2017 03:57:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-nullqueue-using-props-and-transafoms-is-not/m-p/325371#M6652</guid>
      <dc:creator>SagarSplunk</dc:creator>
      <dc:date>2017-07-21T03:57:12Z</dc:date>
    </item>
    <item>
      <title>Re: Sending data to nullqueue using props and transafoms is not working.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-nullqueue-using-props-and-transafoms-is-not/m-p/325372#M6653</link>
      <description>&lt;P&gt;You need an "*" after the first "." to match on more than just one character. You can also skip the last "." Try this:&lt;BR /&gt;
    [eventsDrop]&lt;BR /&gt;
    REGEX = SERVICE-.*E2ELoggingSupport&lt;BR /&gt;
    DEST_KEY = queue&lt;BR /&gt;
    FORMAT = nullQueue&lt;BR /&gt;
Drop it on your indexer and restart Splunk.&lt;/P&gt;

&lt;P&gt;BTW, &lt;A href="http://regexr.com/" target="_blank"&gt;RegExr&lt;/A&gt; is a good tool to test whether your RegEx constructs work. &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 15:00:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-nullqueue-using-props-and-transafoms-is-not/m-p/325372#M6653</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2020-09-29T15:00:17Z</dc:date>
    </item>
    <item>
      <title>Re: Sending data to nullqueue using props and transafoms is not working.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-nullqueue-using-props-and-transafoms-is-not/m-p/325373#M6654</link>
      <description>&lt;P&gt;Hi SSievert&lt;/P&gt;

&lt;P&gt;I tried above Regex its too not working for me are there limitation for free version of splunk.&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jul 2017 06:18:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-nullqueue-using-props-and-transafoms-is-not/m-p/325373#M6654</guid>
      <dc:creator>SagarSplunk</dc:creator>
      <dc:date>2017-07-22T06:18:20Z</dc:date>
    </item>
    <item>
      <title>Re: Sending data to nullqueue using props and transafoms is not working.</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-nullqueue-using-props-and-transafoms-is-not/m-p/325374#M6655</link>
      <description>&lt;P&gt;There are &lt;A href="https://www.splunk.com/en_us/products/splunk-enterprise/free-vs-enterprise.html"&gt;limitations in the free version&lt;/A&gt; of Splunk, but this is not one of them.&lt;BR /&gt;
If you make sure that&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;the stanza name in props.conf matches your sourcetype and&lt;/LI&gt;
&lt;LI&gt;the stanza name in transforms matches what you used after TRANSFORMS-xxxx= and&lt;/LI&gt;
&lt;LI&gt;your RegEx works and matches what you want to match and&lt;/LI&gt;
&lt;LI&gt;you deploy props/transforms in the right place (where parsing happens, i.e. indexer or heavy forwarder, NOT universal forwarder)&lt;/LI&gt;
&lt;LI&gt;you restart splunk or &lt;A href="https://answers.splunk.com/answers/102568/reload-transforms-conf-without-restarting-splunk.html"&gt;reload the configuration&lt;/A&gt; after making the change&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;this will work with any version of Splunk Enterprise.&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jul 2017 18:03:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise/Sending-data-to-nullqueue-using-props-and-transafoms-is-not/m-p/325374#M6655</guid>
      <dc:creator>s2_splunk</dc:creator>
      <dc:date>2017-07-22T18:03:26Z</dc:date>
    </item>
  </channel>
</rss>

