<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What are the configurations required to forward specific log messages to Splunk? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-configurations-required-to-forward-specific-log/m-p/573180#M101388</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&amp;nbsp;,Please find the answers below.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;what architecture do you have: stand-alone or distributed?&amp;nbsp;&lt;STRONG&gt;Stand-alone&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;which kind of logs are you speaking of (wineventlog, syslog, linux, firewall, etc...)?&amp;nbsp;&lt;STRONG&gt;Application logs&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;do you want to find the word "ScanStatistics" searching in your logs or do you want to index only the logs containing this word?&amp;nbsp;&lt;STRONG&gt;Yes, we want to index/forward logs which contains word "ScanStatistics".&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;how do you ingest your logs, or you're not able to ingest logs and this is your main question?&lt;STRONG&gt;No, we use splunk forwarder to ingest logs. But here I need specific configuartions required to forward only "Scanstatistics" logs to splunk terminating all other log&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;could you share some example of your logs?&amp;nbsp;&lt;STRONG&gt;&lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;PRE&gt;&lt;SPAN&gt;&lt;SPAN&gt;2021-10-28 01:31:47,535 - cm_scan_statistics.cm_scan_statistics - INFO - c0:a0:0d:06:5b:c7 - CmScanStatistics. CM(c0:a0:0d:06:5b:c7) fbc.status=SUCCESS&lt;BR /&gt;&lt;SPAN&gt;2021-10-28 01:31:47,535 - cm_scan_statistics.cm_scan_statistics - INFO - c0:a0:0d:06:5b:c7 - CmScanStatistics: updating cm(c0:a0:0d:06:5b:c7) for ['metadata.scans.success', 'metadata.scans.lastupdate', 'metadata.scans.lastevent']&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;In few words,&amp;nbsp;I need to understand:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the kind of logs you're speaking;&amp;nbsp;&lt;STRONG&gt;Application logs&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;if you need an help in searching the word in your logs or in ingesting and indexing logs.&lt;P&gt;because:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;knowing the kind of your logs I can suggest the best way to ingest and parse your logs;&lt;/LI&gt;&lt;LI&gt;if you're speaking of a search, I can hint the search to find the events that contain the above word;&lt;/LI&gt;&lt;LI&gt;if you're speaking of ingesting logs, I can hint how to ingest, parse and eventually filter your logs.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 01 Nov 2021 15:10:43 GMT</pubDate>
    <dc:creator>ssoftility</dc:creator>
    <dc:date>2021-11-01T15:10:43Z</dc:date>
    <item>
      <title>What are the configurations required to forward specific log messages to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-configurations-required-to-forward-specific-log/m-p/572946#M101365</link>
      <description>&lt;P&gt;What are the configurations required to forward specific log messages to Splunk.&lt;/P&gt;&lt;P&gt;Every&amp;nbsp; log message that contains "&lt;STRONG&gt;ScanStatistics&lt;/STRONG&gt;" this phrase needs to get forwarded to Splunk.&lt;BR /&gt;Let us know what are the configurations to be done.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Oct 2021 12:54:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-configurations-required-to-forward-specific-log/m-p/572946#M101365</guid>
      <dc:creator>ssoftility</dc:creator>
      <dc:date>2021-10-29T12:54:29Z</dc:date>
    </item>
    <item>
      <title>Re: What are the configurations required to forward specific log messages to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-configurations-required-to-forward-specific-log/m-p/572952#M101366</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240197"&gt;@ssoftility&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;some additional information, please:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;what architecture do you have: stand-alone or distributed?&lt;/LI&gt;&lt;LI&gt;which kind of logs are you speaking of (wineventlog, syslog, linux, firewall, etc...)?&lt;/LI&gt;&lt;LI&gt;do you want to find the word "ScanStatistics" searching in your logs or do you want to index only the logs containing this word?&lt;/LI&gt;&lt;LI&gt;how do you ingest your logs, or you're not able to ingest logs and this is your main question?&lt;/LI&gt;&lt;LI&gt;could you share some example of your logs?&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In few words,&amp;nbsp;I need to understand:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the kind of logs you're speaking;&lt;/LI&gt;&lt;LI&gt;if you need an help in searching the word in your logs or in ingesting and indexing logs.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;because:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;knowing the kind of your logs I can suggest the best way to ingest and parse your logs;&lt;/LI&gt;&lt;LI&gt;if you're speaking of a search, I can hint the search to find the events that contain the above word;&lt;/LI&gt;&lt;LI&gt;if you're speaking of ingesting logs, I can hint how to ingest, parse and eventually filter your logs.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Oct 2021 13:07:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-configurations-required-to-forward-specific-log/m-p/572952#M101366</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-10-29T13:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: What are the configurations required to forward specific log messages to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-configurations-required-to-forward-specific-log/m-p/573180#M101388</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&amp;nbsp;,Please find the answers below.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;what architecture do you have: stand-alone or distributed?&amp;nbsp;&lt;STRONG&gt;Stand-alone&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;which kind of logs are you speaking of (wineventlog, syslog, linux, firewall, etc...)?&amp;nbsp;&lt;STRONG&gt;Application logs&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;do you want to find the word "ScanStatistics" searching in your logs or do you want to index only the logs containing this word?&amp;nbsp;&lt;STRONG&gt;Yes, we want to index/forward logs which contains word "ScanStatistics".&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;how do you ingest your logs, or you're not able to ingest logs and this is your main question?&lt;STRONG&gt;No, we use splunk forwarder to ingest logs. But here I need specific configuartions required to forward only "Scanstatistics" logs to splunk terminating all other log&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;could you share some example of your logs?&amp;nbsp;&lt;STRONG&gt;&lt;STRONG&gt;Yes&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;PRE&gt;&lt;SPAN&gt;&lt;SPAN&gt;2021-10-28 01:31:47,535 - cm_scan_statistics.cm_scan_statistics - INFO - c0:a0:0d:06:5b:c7 - CmScanStatistics. CM(c0:a0:0d:06:5b:c7) fbc.status=SUCCESS&lt;BR /&gt;&lt;SPAN&gt;2021-10-28 01:31:47,535 - cm_scan_statistics.cm_scan_statistics - INFO - c0:a0:0d:06:5b:c7 - CmScanStatistics: updating cm(c0:a0:0d:06:5b:c7) for ['metadata.scans.success', 'metadata.scans.lastupdate', 'metadata.scans.lastevent']&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/PRE&gt;&lt;P&gt;In few words,&amp;nbsp;I need to understand:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;the kind of logs you're speaking;&amp;nbsp;&lt;STRONG&gt;Application logs&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;if you need an help in searching the word in your logs or in ingesting and indexing logs.&lt;P&gt;because:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;knowing the kind of your logs I can suggest the best way to ingest and parse your logs;&lt;/LI&gt;&lt;LI&gt;if you're speaking of a search, I can hint the search to find the events that contain the above word;&lt;/LI&gt;&lt;LI&gt;if you're speaking of ingesting logs, I can hint how to ingest, parse and eventually filter your logs.&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161352"&gt;@gcusello&lt;/a&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 15:10:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-configurations-required-to-forward-specific-log/m-p/573180#M101388</guid>
      <dc:creator>ssoftility</dc:creator>
      <dc:date>2021-11-01T15:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: What are the configurations required to forward specific log messages to Splunk?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-are-the-configurations-required-to-forward-specific-log/m-p/573210#M101393</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/240197"&gt;@ssoftility&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if you want to filter your logs before indexing, you surely use less license for these logs but you have less logs for your searches: you cannot use the discarded logs.&lt;/P&gt;&lt;P&gt;Anyway, with the only exception of WindEventLogs, logs can be filtered only on indexers or (when present) on heavy Forwarders.&lt;/P&gt;&lt;P&gt;To do this, you have to follow the instructions at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.3/Forwarding/Routeandfilterdatad#Keep_specific_events_and_discard_the_rest" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.3/Forwarding/Routeandfilterdatad#Keep_specific_events_and_discard_the_rest&lt;/A&gt;&lt;/P&gt;&lt;P&gt;in few word, on you Indexers you have to create a props.conf file containing:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[your_sourcetype]
TRANSFORMS-set= setnull,setparsing&lt;/LI-CODE&gt;&lt;P&gt;and a trandforms.conf like this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[setnull]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue

[setparsing]
REGEX = CmScanStatistics
DEST_KEY = queue
FORMAT = indexQueue&lt;/LI-CODE&gt;&lt;P&gt;In this way you discard all logs except the ones containing "CmScanStatistics".&lt;/P&gt;&lt;P&gt;Remember to restart Splunk if you manually modify files.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 17:37:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-are-the-configurations-required-to-forward-specific-log/m-p/573210#M101393</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2021-11-01T17:37:58Z</dc:date>
    </item>
  </channel>
</rss>

