<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [udp://:portnumber] Event Blacklist in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/udp-portnumber-Event-Blacklist-How-do-I-prevent-unwanted-data/m-p/613039#M106073</link>
    <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/190949"&gt;@maciep&lt;/a&gt;&amp;nbsp;Ok after some test i figured out how to make it work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;PROPS&lt;/P&gt;&lt;PRE&gt;[fgt_log]&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;                   #here you have to put the sourcetype of your data, not the source like the documentation tells you&lt;BR /&gt;TRANSFORMS-null = transnull&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #reference to the transform stanza for the nullqueue &amp;nbsp;&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;here the syntax is TRANSFORMS-&amp;lt;class&amp;gt; and for what i have understood the &amp;lt;class&amp;gt;name can be anything you want (except some special characters, if I'm not mistaken), same for the stanza name in the transform.&lt;/P&gt;&lt;P&gt;TRANSFORMS&lt;/P&gt;&lt;PRE&gt;[transnull]&lt;BR /&gt;REGEX = (dstip=(?:8\.8\.8\.8|8\.8\.4\.4)[^D]+D(?:NS)?(?:[^D\n]+DNS)?)&lt;BR /&gt;DEST_KEY = queue&lt;BR /&gt;FORMAT = nullQueue&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;Here i had a bit of trouble with the regex syntax but in the end i made it work. DEST_KEY like the documentation says, same for FORMAT. The name of the stanza is the same called in the props.conf.&lt;/P&gt;&lt;P&gt;INPUTS&lt;/P&gt;&lt;PRE&gt;[udp://:myport]&lt;BR /&gt;sourcetype = fgt_log&lt;BR /&gt;source = ***&lt;BR /&gt;index = ***&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;With this it works all perfectly. Thaks again for the support&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/190949"&gt;@maciep&lt;/a&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 14 Sep 2022 09:15:05 GMT</pubDate>
    <dc:creator>LinghGroove</dc:creator>
    <dc:date>2022-09-14T09:15:05Z</dc:date>
    <item>
      <title>[udp://:portnumber] Event Blacklist- How do I prevent unwanted data from being indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/udp-portnumber-Event-Blacklist-How-do-I-prevent-unwanted-data/m-p/612584#M105998</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I am currently receiving firewall data on my heavy forwarder on a specific port number. On the HF there is an simple inputs.conf with&lt;/P&gt;
&lt;PRE&gt;[udp://:portnumber]&lt;BR /&gt;sourcetype=fgt_log&lt;BR /&gt;index=fw_data&lt;/PRE&gt;
&lt;P&gt;and an outputs.conf that sends all to the indexers. The problem is that i am receiving a lot of garbage traffic (like DNS traffic to 8.8.8.8 or 8.8.4.4). I don't want to index this data. I don't have access to the firewall so i can't just stop it there.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I thought that a blacklist would stop the events from coming. (I tried a simple blacklist like the ones used under the [monitor] stanza. Something like this:&amp;nbsp;blacklist=(dstip=8\.8\.8\.8|dstip=8\.8\.4\.4|service="DNS"))&lt;/P&gt;
&lt;P&gt;Unfortunately it didn't work... I made some research but i only found the "acceptFrom" that in this situation i don't think it's useful. Came across this post but wasn't useful&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Blacklist-a-host-hosts-is-sending-logs-to-Splunk-via-TCP/m-p/289283" target="_self"&gt;https://community.splunk.com/t5/Getting-Data-In/Blacklist-a-host-hosts-is-sending-logs-to-Splunk-via-TCP/m-p/289283&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Any tips?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2022 15:37:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/udp-portnumber-Event-Blacklist-How-do-I-prevent-unwanted-data/m-p/612584#M105998</guid>
      <dc:creator>LinghGroove</dc:creator>
      <dc:date>2022-09-14T15:37:47Z</dc:date>
    </item>
    <item>
      <title>Re: [udp://:portnumber] Event Blacklist</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/udp-portnumber-Event-Blacklist-How-do-I-prevent-unwanted-data/m-p/612596#M105999</link>
      <description>&lt;P&gt;I am not sure about the udp input stanza and whether you can blacklist there or not.&amp;nbsp; But a common approach is to use props/transforms to filter matching events to the "nullQueue" so that they are not ingested.&amp;nbsp; That is something that can be done on the heavy forwarder.&lt;/P&gt;&lt;P&gt;You can find details in the docs about it but also probably quite a few posts out here detailing the steps...&lt;BR /&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.0.1/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues" target="_blank"&gt;Route and filter data - Splunk Documentation&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 15:14:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/udp-portnumber-Event-Blacklist-How-do-I-prevent-unwanted-data/m-p/612596#M105999</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2022-09-09T15:14:13Z</dc:date>
    </item>
    <item>
      <title>Re: [udp://:portnumber] Event Blacklist</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/udp-portnumber-Event-Blacklist-How-do-I-prevent-unwanted-data/m-p/612602#M106001</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/190949"&gt;@maciep&lt;/a&gt;&amp;nbsp;thanks for your reply,&lt;/P&gt;&lt;P&gt;I have tried the solution you are suggesting... unfortunatly i am not able to make it work... I just now tried the solution from&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/How-could-i-filter-network-firewall-data-using-a-filed-value/m-p/284542" target="_self"&gt;https://community.splunk.com/t5/Getting-Data-In/How-could-i-filter-network-firewall-data-using-a-filed-value/m-p/284542&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The problem presented in this question is nearly identical. I tried to apply it just as they answered but i doesn't work. Maybe i'm setting something wrong or maybe i am putting a wrong regex. If i'll make it work i will write you back here.&lt;/P&gt;&lt;P&gt;Thanks again&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 09 Sep 2022 15:21:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/udp-portnumber-Event-Blacklist-How-do-I-prevent-unwanted-data/m-p/612602#M106001</guid>
      <dc:creator>LinghGroove</dc:creator>
      <dc:date>2022-09-09T15:21:16Z</dc:date>
    </item>
    <item>
      <title>Re: [udp://:portnumber] Event Blacklist</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/udp-portnumber-Event-Blacklist-How-do-I-prevent-unwanted-data/m-p/613039#M106073</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/190949"&gt;@maciep&lt;/a&gt;&amp;nbsp;Ok after some test i figured out how to make it work.&amp;nbsp;&lt;/P&gt;&lt;P&gt;PROPS&lt;/P&gt;&lt;PRE&gt;[fgt_log]&amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;                   #here you have to put the sourcetype of your data, not the source like the documentation tells you&lt;BR /&gt;TRANSFORMS-null = transnull&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; #reference to the transform stanza for the nullqueue &amp;nbsp;&amp;nbsp;&lt;/PRE&gt;&lt;P&gt;here the syntax is TRANSFORMS-&amp;lt;class&amp;gt; and for what i have understood the &amp;lt;class&amp;gt;name can be anything you want (except some special characters, if I'm not mistaken), same for the stanza name in the transform.&lt;/P&gt;&lt;P&gt;TRANSFORMS&lt;/P&gt;&lt;PRE&gt;[transnull]&lt;BR /&gt;REGEX = (dstip=(?:8\.8\.8\.8|8\.8\.4\.4)[^D]+D(?:NS)?(?:[^D\n]+DNS)?)&lt;BR /&gt;DEST_KEY = queue&lt;BR /&gt;FORMAT = nullQueue&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;Here i had a bit of trouble with the regex syntax but in the end i made it work. DEST_KEY like the documentation says, same for FORMAT. The name of the stanza is the same called in the props.conf.&lt;/P&gt;&lt;P&gt;INPUTS&lt;/P&gt;&lt;PRE&gt;[udp://:myport]&lt;BR /&gt;sourcetype = fgt_log&lt;BR /&gt;source = ***&lt;BR /&gt;index = ***&lt;/PRE&gt;&lt;P&gt;&amp;nbsp;With this it works all perfectly. Thaks again for the support&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/190949"&gt;@maciep&lt;/a&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2022 09:15:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/udp-portnumber-Event-Blacklist-How-do-I-prevent-unwanted-data/m-p/613039#M106073</guid>
      <dc:creator>LinghGroove</dc:creator>
      <dc:date>2022-09-14T09:15:05Z</dc:date>
    </item>
    <item>
      <title>Re: [udp://:portnumber] Event Blacklist</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/udp-portnumber-Event-Blacklist-How-do-I-prevent-unwanted-data/m-p/613052#M106074</link>
      <description>&lt;P&gt;There used to be a really good .conf presentation on regex, but I guess Splunk decided to remove all of the old .conf content from their site....such a shame.&amp;nbsp; Glad you were able to make it work!&lt;/P&gt;</description>
      <pubDate>Wed, 14 Sep 2022 11:10:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/udp-portnumber-Event-Blacklist-How-do-I-prevent-unwanted-data/m-p/613052#M106074</guid>
      <dc:creator>maciep</dc:creator>
      <dc:date>2022-09-14T11:10:38Z</dc:date>
    </item>
  </channel>
</rss>

