<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: keep some events and discard the rest in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/keep-some-events-and-discard-the-rest/m-p/56031#M10945</link>
    <description>&lt;P&gt;I'm sure you can optimize your regex to match multiple criteria.  Can you provide examples of the events you're trying to filter?&lt;/P&gt;</description>
    <pubDate>Wed, 05 Jun 2013 23:44:12 GMT</pubDate>
    <dc:creator>carmackd</dc:creator>
    <dc:date>2013-06-05T23:44:12Z</dc:date>
    <item>
      <title>keep some events and discard the rest</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/keep-some-events-and-discard-the-rest/m-p/56030#M10944</link>
      <description>&lt;P&gt;i have a huge log file with events, i need to keep around 20-30 events and discard the rest. I have used a stanza in transforms.conf with a REGEX=(MATCH-1 | MATCH-2 | MATCH-3 |..|..|... MATCH-N), such that the events which match with REGEX are in and the rest are sent to nullQueue. &lt;/P&gt;

&lt;P&gt;Is there a better way to write instead of writing (MATCH-1 | MATCH-2 | MATCH-3 |..|..|... MATCH-N) in the REGEX?&lt;/P&gt;

&lt;P&gt;Please guide..&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2013 16:32:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/keep-some-events-and-discard-the-rest/m-p/56030#M10944</guid>
      <dc:creator>trkalva</dc:creator>
      <dc:date>2013-06-05T16:32:22Z</dc:date>
    </item>
    <item>
      <title>Re: keep some events and discard the rest</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/keep-some-events-and-discard-the-rest/m-p/56031#M10945</link>
      <description>&lt;P&gt;I'm sure you can optimize your regex to match multiple criteria.  Can you provide examples of the events you're trying to filter?&lt;/P&gt;</description>
      <pubDate>Wed, 05 Jun 2013 23:44:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/keep-some-events-and-discard-the-rest/m-p/56031#M10945</guid>
      <dc:creator>carmackd</dc:creator>
      <dc:date>2013-06-05T23:44:12Z</dc:date>
    </item>
  </channel>
</rss>

