<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How to write props.conf / transforms.conf to filter out ICMP events? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-write-props-conf-transforms-conf-to-filter-out-ICMP/m-p/604928#M105176</link>
    <description>&lt;P&gt;We have a home grown application that pings Google DNS on a regular basis.&amp;nbsp; We are ingesting the data from our Meraki wireless devices and I would like to filter out the ICMP messages with the destination of 8.8.8.8.&amp;nbsp; Our events look like this:&lt;/P&gt;
&lt;P&gt;7/8/22&lt;BR /&gt;8:14:51.427 AM&lt;BR /&gt;2022-07-08 07:14:51.427 xxx.xxx.xxx.xxx 1 Location_XXX flows src=xxx.xxx.0.1 dst=8.8.8.8 mac=70:D3:79:XX:XX:XX protocol=icmp type=8 pattern: allow icmp&lt;BR /&gt;host = xxx.xx.0.2source = /syslog0/syslog/meraki/xxx.xx.0.2/messages.log sourcetype = meraki&lt;/P&gt;
&lt;P&gt;What would be the most efficient way to filter these messages to help reduce license usage?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 08 Jul 2022 14:19:43 GMT</pubDate>
    <dc:creator>leejones4</dc:creator>
    <dc:date>2022-07-08T14:19:43Z</dc:date>
    <item>
      <title>How to write props.conf / transforms.conf to filter out ICMP events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-write-props-conf-transforms-conf-to-filter-out-ICMP/m-p/604928#M105176</link>
      <description>&lt;P&gt;We have a home grown application that pings Google DNS on a regular basis.&amp;nbsp; We are ingesting the data from our Meraki wireless devices and I would like to filter out the ICMP messages with the destination of 8.8.8.8.&amp;nbsp; Our events look like this:&lt;/P&gt;
&lt;P&gt;7/8/22&lt;BR /&gt;8:14:51.427 AM&lt;BR /&gt;2022-07-08 07:14:51.427 xxx.xxx.xxx.xxx 1 Location_XXX flows src=xxx.xxx.0.1 dst=8.8.8.8 mac=70:D3:79:XX:XX:XX protocol=icmp type=8 pattern: allow icmp&lt;BR /&gt;host = xxx.xx.0.2source = /syslog0/syslog/meraki/xxx.xx.0.2/messages.log sourcetype = meraki&lt;/P&gt;
&lt;P&gt;What would be the most efficient way to filter these messages to help reduce license usage?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 14:19:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-write-props-conf-transforms-conf-to-filter-out-ICMP/m-p/604928#M105176</guid>
      <dc:creator>leejones4</dc:creator>
      <dc:date>2022-07-08T14:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: props.conf / transforms.conf to filter out ICMP events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-write-props-conf-transforms-conf-to-filter-out-ICMP/m-p/604929#M105177</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/224844"&gt;@leejones4&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;the question is:do you want to filter the full message or a part of it?&lt;/P&gt;&lt;P&gt;If the full message, see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues&lt;/A&gt;&lt;/P&gt;&lt;P&gt;In other words:&lt;/P&gt;&lt;P&gt;if to reduce the event, you can see at&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/latest/Data/Anonymizedata" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/latest/Data/Anonymizedata&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Remember than in both ways you cannot use more the discarded events or parte of events.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 12:27:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-write-props-conf-transforms-conf-to-filter-out-ICMP/m-p/604929#M105177</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2022-07-08T12:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: props.conf / transforms.conf to filter out ICMP events</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-write-props-conf-transforms-conf-to-filter-out-ICMP/m-p/604934#M105179</link>
      <description>&lt;P&gt;Thank you for the quick response.&amp;nbsp; I am looking to drop any events that have the ICMP to 8.8.8.8 destination.&amp;nbsp; I appreciate the information links.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Jul 2022 12:45:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-write-props-conf-transforms-conf-to-filter-out-ICMP/m-p/604934#M105179</guid>
      <dc:creator>leejones4</dc:creator>
      <dc:date>2022-07-08T12:45:07Z</dc:date>
    </item>
  </channel>
</rss>

