<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: forwarded data remove timestamp and host in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/forwarded-data-remove-timestamp-and-host/m-p/690280#M28280</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266570"&gt;@KhalidAlharthi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can do this with PREAMBLE_REGEX in props.conf&lt;/P&gt;&lt;PRE&gt;PREAMBLE_REGEX = &amp;lt;regex&amp;gt;
* A regular expression that lets Splunk software ignore "preamble lines",
  or lines that occur before lines that represent structured data.
* When set, Splunk software ignores these preamble lines,
  based on the pattern you specify.
* Default: not set&lt;/PRE&gt;</description>
    <pubDate>Mon, 10 Jun 2024 22:52:40 GMT</pubDate>
    <dc:creator>KendallW</dc:creator>
    <dc:date>2024-06-10T22:52:40Z</dc:date>
    <item>
      <title>forwarded data remove timestamp and host</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/forwarded-data-remove-timestamp-and-host/m-p/690278#M28279</link>
      <description>&lt;P&gt;is there a way to remove the header comes with non syslog source types that include hostname and timestamp with priority at the begnning of the event sended&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have configuered outputs.conf,props.conf,transforms.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;is there a way to remove the priority and hostname associated with timestamp on the third-party system&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 22:26:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/forwarded-data-remove-timestamp-and-host/m-p/690278#M28279</guid>
      <dc:creator>KhalidAlharthi</dc:creator>
      <dc:date>2024-06-10T22:26:15Z</dc:date>
    </item>
    <item>
      <title>Re: forwarded data remove timestamp and host</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/forwarded-data-remove-timestamp-and-host/m-p/690280#M28280</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266570"&gt;@KhalidAlharthi&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You can do this with PREAMBLE_REGEX in props.conf&lt;/P&gt;&lt;PRE&gt;PREAMBLE_REGEX = &amp;lt;regex&amp;gt;
* A regular expression that lets Splunk software ignore "preamble lines",
  or lines that occur before lines that represent structured data.
* When set, Splunk software ignores these preamble lines,
  based on the pattern you specify.
* Default: not set&lt;/PRE&gt;</description>
      <pubDate>Mon, 10 Jun 2024 22:52:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/forwarded-data-remove-timestamp-and-host/m-p/690280#M28280</guid>
      <dc:creator>KendallW</dc:creator>
      <dc:date>2024-06-10T22:52:40Z</dc:date>
    </item>
    <item>
      <title>Re: forwarded data remove timestamp and host</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/forwarded-data-remove-timestamp-and-host/m-p/690281#M28281</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/121137"&gt;@KendallW&lt;/a&gt;&amp;nbsp;Thanks for responding to this matter&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;could you please give example cuz i don't understand it quite good .&lt;/P&gt;&lt;P&gt;for example this log&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Jul 14 14:15:56 10.128.213.50 Jul 14 14:15:56 my-host-int02 snmpd[7777]: Received SNMP packet(s) from UDP: [10.128.30.20]:54900&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;i want to remove the timestamp and host at the beginning of the event&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;this happened because the non syslog source type i guess and i want this to be removed&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 23:04:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/forwarded-data-remove-timestamp-and-host/m-p/690281#M28281</guid>
      <dc:creator>KhalidAlharthi</dc:creator>
      <dc:date>2024-06-10T23:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: forwarded data remove timestamp and host</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/forwarded-data-remove-timestamp-and-host/m-p/690284#M28282</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/266570"&gt;@KhalidAlharthi&lt;/a&gt;&amp;nbsp;try this in props.conf (on indexer or HF)&lt;BR /&gt;PREAMBLE_REGEX =&amp;nbsp;\w{3}\s(\d{2}[\s\:]){4}(\d{1,3}\.){3}\d{1,3}\s\w{3}\s(\d{2}[\s\:]){4}[^\s]+\s&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 23:19:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/forwarded-data-remove-timestamp-and-host/m-p/690284#M28282</guid>
      <dc:creator>KendallW</dc:creator>
      <dc:date>2024-06-10T23:19:31Z</dc:date>
    </item>
    <item>
      <title>Re: forwarded data remove timestamp and host</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/forwarded-data-remove-timestamp-and-host/m-p/690285#M28283</link>
      <description>&lt;P&gt;Can you see your private messages if you don't mind&lt;/P&gt;</description>
      <pubDate>Mon, 10 Jun 2024 23:48:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/forwarded-data-remove-timestamp-and-host/m-p/690285#M28283</guid>
      <dc:creator>KhalidAlharthi</dc:creator>
      <dc:date>2024-06-10T23:48:36Z</dc:date>
    </item>
  </channel>
</rss>

