<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: transform.conf in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/transform-conf/m-p/651087#M110596</link>
    <description>&lt;P&gt;Essentially you need a regex to identify the events you want to filter (or route)&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.0/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues" target="_self"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.0/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 19 Jul 2023 08:07:56 GMT</pubDate>
    <dc:creator>ITWhisperer</dc:creator>
    <dc:date>2023-07-19T08:07:56Z</dc:date>
    <item>
      <title>transform.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/transform-conf/m-p/651079#M110592</link>
      <description>&lt;P&gt;how can i modify the transforms.conf file so that when i ingest the data it throws away all the events that have the status FAILED after the first ip address&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 07:38:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/transform-conf/m-p/651079#M110592</guid>
      <dc:creator>lorscardala985</dc:creator>
      <dc:date>2023-07-19T07:38:07Z</dc:date>
    </item>
    <item>
      <title>Re: transform.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/transform-conf/m-p/651085#M110594</link>
      <description>&lt;P&gt;You need to identify these events and direct them to a null queue&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 07:55:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/transform-conf/m-p/651085#M110594</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-07-19T07:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: transform.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/transform-conf/m-p/651086#M110595</link>
      <description>&lt;P&gt;how can i identify, because i have file with log events, and i&amp;nbsp; need to ingest on splunk&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 07:59:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/transform-conf/m-p/651086#M110595</guid>
      <dc:creator>lorscardala985</dc:creator>
      <dc:date>2023-07-19T07:59:14Z</dc:date>
    </item>
    <item>
      <title>Re: transform.conf</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/transform-conf/m-p/651087#M110596</link>
      <description>&lt;P&gt;Essentially you need a regex to identify the events you want to filter (or route)&lt;/P&gt;&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/9.1.0/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues" target="_self"&gt;https://docs.splunk.com/Documentation/Splunk/9.1.0/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 Jul 2023 08:07:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/transform-conf/m-p/651087#M110596</guid>
      <dc:creator>ITWhisperer</dc:creator>
      <dc:date>2023-07-19T08:07:56Z</dc:date>
    </item>
  </channel>
</rss>

