<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to exclude specific events from single computer (deployment client)? in Deployment Architecture</title>
    <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-exclude-specific-events-from-single-computer-deployment/m-p/257296#M9776</link>
    <description>&lt;P&gt;Similar example on SPlunk Doc &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad#Keep_specific_events_and_discard_the_rest"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad#Keep_specific_events_and_discard_the_rest&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;This can be done for &lt;CODE&gt;[yoursourcetype]&lt;/CODE&gt;  OR &lt;CODE&gt;[source::yoursource]&lt;/CODE&gt; OR &lt;CODE&gt;[host::yourhost]&lt;/CODE&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Mar 2016 14:22:59 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2016-03-23T14:22:59Z</dc:date>
    <item>
      <title>How to exclude specific events from single computer (deployment client)?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-exclude-specific-events-from-single-computer-deployment/m-p/257294#M9774</link>
      <description>&lt;P&gt;Configuration is controlled by deployment server -&amp;gt; deployment clients.  How can a specific event (by event id, or other search criteria) for a single computer be excluded?&lt;/P&gt;

&lt;P&gt;Recently a computer (deployment client) had a failed hard drive which resulted in over 100K messages per day.  This quickly exceeded our quota.  How can problem events be excluded from the configuration for a single client until the problem is resolved?  Ideally only the problem events would be excluded, as we want to continue receiving all other messages which may indicate any new problems during the repair window.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Mar 2016 23:34:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-exclude-specific-events-from-single-computer-deployment/m-p/257294#M9774</guid>
      <dc:creator>timcityspan</dc:creator>
      <dc:date>2016-03-22T23:34:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude specific events from single computer (deployment client)?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-exclude-specific-events-from-single-computer-deployment/m-p/257295#M9775</link>
      <description>&lt;P&gt;Hello &lt;/P&gt;

&lt;P&gt;It depends if the client is a Heavy or Universal Forwarder. In any case you can accomplish this by sending those events to the null queue, using props and transforms. The only difference is, In the HF you put those configuration files on the HF, with the UF those configuration files but reside in the indexer(s). And be sure to define the props stanza for the particular host you want to filter out&lt;/P&gt;

&lt;P&gt;Check this answers to get examples on how to filter out the events:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/59370/filtering-events-using-nullqueue.html"&gt;https://answers.splunk.com/answers/59370/filtering-events-using-nullqueue.html&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2016 08:08:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-exclude-specific-events-from-single-computer-deployment/m-p/257295#M9775</guid>
      <dc:creator>gfuente</dc:creator>
      <dc:date>2016-03-23T08:08:52Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude specific events from single computer (deployment client)?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-exclude-specific-events-from-single-computer-deployment/m-p/257296#M9776</link>
      <description>&lt;P&gt;Similar example on SPlunk Doc &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad#Keep_specific_events_and_discard_the_rest"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad#Keep_specific_events_and_discard_the_rest&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;This can be done for &lt;CODE&gt;[yoursourcetype]&lt;/CODE&gt;  OR &lt;CODE&gt;[source::yoursource]&lt;/CODE&gt; OR &lt;CODE&gt;[host::yourhost]&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2016 14:22:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-exclude-specific-events-from-single-computer-deployment/m-p/257296#M9776</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2016-03-23T14:22:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to exclude specific events from single computer (deployment client)?</title>
      <link>https://community.splunk.com/t5/Deployment-Architecture/How-to-exclude-specific-events-from-single-computer-deployment/m-p/257297#M9777</link>
      <description>&lt;P&gt;It should be noted that this will only affect data after the transform is created.  Any data prior to the transform was not filtered.  Unfortunately this incident filled up the drive on the Splunk server, so we ended up deleting everything and starting over.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2016 16:48:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Deployment-Architecture/How-to-exclude-specific-events-from-single-computer-deployment/m-p/257297#M9777</guid>
      <dc:creator>timcityspan</dc:creator>
      <dc:date>2016-03-23T16:48:21Z</dc:date>
    </item>
  </channel>
</rss>

