<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to filter out lines that start with # in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-out-lines-that-start-with/m-p/575339#M101695</link>
    <description>&lt;P&gt;Hash is a character used for comments both in your logs and splunk config files. You might try escaping it.&lt;/P&gt;</description>
    <pubDate>Wed, 17 Nov 2021 21:29:21 GMT</pubDate>
    <dc:creator>PickleRick</dc:creator>
    <dc:date>2021-11-17T21:29:21Z</dc:date>
    <item>
      <title>How to filter out lines that start with #</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-out-lines-that-start-with/m-p/575336#M101693</link>
      <description>&lt;P&gt;We have logs , where first few lines start with "#" and we don't need to ingest these lines.&amp;nbsp;&lt;/P&gt;&lt;P&gt;We tired to use different methods , that didn't work. Appreciated the help/ideas from splunkers:&lt;/P&gt;&lt;P&gt;1st idea: use PREAMBLE_REGEX = ^#.* in props.conf&amp;nbsp; on Heavy Forwarders where data are being parsed&lt;/P&gt;&lt;P&gt;2nd idea : use TRANSFORMS-null = setnull in props.conf&amp;nbsp; and transforms.conf&lt;BR /&gt;&lt;SPAN&gt;on Heavy Forwarders&amp;nbsp;where data are being parsed&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;transforms.conf:&lt;BR /&gt;[setnull]&lt;BR /&gt;REGEX = ^#.*&lt;BR /&gt;DEST_KEY = queue&lt;BR /&gt;FORMAT = nullQueue&lt;BR /&gt;&lt;BR /&gt;example of log:&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;#-----------------------------------------&lt;BR /&gt;#DATE CREATED:&amp;nbsp; 11/02/2021@04:16&lt;BR /&gt;#SUBJECT:&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; REPORT ON THE GENERAL STATUS OF AUTOSYS JOBS&lt;BR /&gt;#ENVIRONMENT:&amp;nbsp; &amp;nbsp;CBA&lt;BR /&gt;#-----------------------------------------&lt;BR /&gt;&lt;BR /&gt;11/02/2021@04:16,CBA,OTHER,CBA_CLIENT_REPORT_BOX,OI&lt;BR /&gt;11/02/2021@04:16,CBA,OTHER,CBA_copy_file_job,OI&lt;BR /&gt;11/02/2021@04:16,CBA,OTHER,CBA_ABC_SCHEDULER_BOX,OI&lt;BR /&gt;11/02/2021@04:16,CBA,OTHER,CBA_ABC_REPORT_BOX,OI&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 21:08:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-out-lines-that-start-with/m-p/575336#M101693</guid>
      <dc:creator>mlevsh</dc:creator>
      <dc:date>2021-11-17T21:08:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter out lines that start with #</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-out-lines-that-start-with/m-p/575339#M101695</link>
      <description>&lt;P&gt;Hash is a character used for comments both in your logs and splunk config files. You might try escaping it.&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 21:29:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-out-lines-that-start-with/m-p/575339#M101695</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2021-11-17T21:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter out lines that start with #</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-out-lines-that-start-with/m-p/575354#M101699</link>
      <description>&lt;P data-unlink="true"&gt;Hi P&lt;SPAN class=""&gt;&lt;SPAN class=""&gt;ickleRick,&lt;BR /&gt;&lt;BR /&gt;Thank you for suggestion. Unfortunately , it didn't work&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P data-unlink="true"&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 17 Nov 2021 23:54:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-out-lines-that-start-with/m-p/575354#M101699</guid>
      <dc:creator>mlevsh</dc:creator>
      <dc:date>2021-11-17T23:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: How to filter out lines that start with #</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-out-lines-that-start-with/m-p/575370#M101705</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/184259"&gt;@mlevsh&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Try this for preamble_regex. It works.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;PREAMBLE_REGEX=#&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="bhargavi_0-1637214105272.png" style="width: 400px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/16899i8B89AF0C91AB5E22/image-size/medium?v=v2&amp;amp;px=400" role="button" title="bhargavi_0-1637214105272.png" alt="bhargavi_0-1637214105272.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If this helps, give thumbs-up &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#008000"&gt;Happy Splunking!!&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 18 Nov 2021 05:42:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-filter-out-lines-that-start-with/m-p/575370#M101705</guid>
      <dc:creator>bhargavi</dc:creator>
      <dc:date>2021-11-18T05:42:00Z</dc:date>
    </item>
  </channel>
</rss>

