<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: props and transform file modification issue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670375#M112409</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;props.conf and transforms.conf are located on our splunk enterprise server on "splunk add on for AWS" app path; that is "&lt;/SPAN&gt;D:\Program Files\Splunk\etc\apps\Splunk_TA_aws\local"&lt;/P&gt;</description>
    <pubDate>Thu, 30 Nov 2023 17:32:00 GMT</pubDate>
    <dc:creator>roopeshetty</dc:creator>
    <dc:date>2023-11-30T17:32:00Z</dc:date>
    <item>
      <title>props and transform file modification issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670345#M112398</link>
      <description>&lt;P&gt;Hi Guys,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In Splunk a field by name “&lt;STRONG&gt;event_sub_type&lt;/STRONG&gt;” has multiple values. We don’t want to ingest any logs into splunk whose field “&lt;STRONG&gt;event_sub_type&lt;/STRONG&gt;” value is either “&lt;STRONG&gt;WAN Firewall”&lt;/STRONG&gt; or “&lt;STRONG&gt;TLS&lt;/STRONG&gt;” (as marked in attached screen shot) as these are huge unwanted logs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 999px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28317i0A3E7BF4D013023B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our search query is :&amp;nbsp;&lt;STRONG&gt;index=cato sourcetype=cato_source&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We tried multiple ways by editing the &lt;STRONG&gt;props.conf &lt;/STRONG&gt;and &lt;STRONG&gt;transforms.conf&lt;/STRONG&gt; to exclude these logs as below but none of them are successful to exclude those logs;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;props.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[sourcetype::cato_source]&lt;/P&gt;&lt;P&gt;TRANSFORMS-filter_logs = cloudparsing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;transforms.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[cloudparsing]&lt;/P&gt;&lt;P&gt;REGEX = \"event_sub_type\":\"(WAN Firewall|TLS)\"&lt;/P&gt;&lt;P&gt;DEST_KEY = queue&lt;/P&gt;&lt;P&gt;FORMAT = nullQueue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can someone please guide how to exclude these events whose “event_sub_type” value contains either “WAN Firewall” or “TLS” by editing props.conf and transforms.conf?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;RAW Events for reference which needs to be excluded ;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1. event_sub_type":"WAN&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;{"event_count":1,"ISP_name":"Shanghai internet","rule":"Initial Connectivity Rule","dest_is_site_or_vpn":"Site","src_isp_ip":"0.0.0.0","time_str":"2023-11-28T04:27:40Z","src_site":"CHINA-AZURE-E2","src_ip":"0.0.0.1","internalId":"54464646","dest_site_name":"china_112,"event_type":"Security","src_country_code":"CN","action":"Monitor","subnet_name":"cn-001.net-vnet-1","pop_name":"Shanghai_1","dest_port":443,"dest_site":"china_connect","rule_name":"Initial Connectivity Rule&lt;STRONG&gt;","&lt;FONT color="#FF0000"&gt;event_sub_type":"WAN Firewall&lt;/FONT&gt;","&lt;/STRONG&gt;insertionDate":1701188916690,"ip_protocol":"TCP","rule_id":"101238","src_is_site_or_vpn":"Site","account_id":5555,"application":"HTTP(S)","src_site_name":"china_connect","src_country":"China","dest_ip":"0.0.0.0","os_type":"OS_ANDROID","app_stack""TCP","TLS","HTTP(S)"],"time":1701188860834}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2. "event_sub_type":"TLS","&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;{"event_count":4,"http_host_name":"isp.vpn","ISP_name":"China_internet","src_isp_ip":"0.0.0.0","tls_version":"TLSv1.3","time_str":"2023-11-28T04:27:16Z","src_site":"china_mtt","src_ip":"0.0.0.0","internalId":"rtrgrtr","domain_name":"&lt;A href="https://l.facebook.com/l.php?u=http%3A%2F%2Fchina.gh.com%2F%3Ffbclid%3DIwAR1FLHkH7Epa46b8tqtr_XSosACQ2uiHfd4aOwmNg2Zn3kr5tKZG_nywfTg&amp;amp;h=AT19PKkLQvWltCvNFPUiYrp45Qq_uDiBoDYjk2e7-_GBMSWTys6zDv9Co7nMgza1vWhoDoiyp8WpkL_rmtd0f5K3skkN3wonld2wG-8wRHsv6Lyw_NJ2OiooHjPAbWdUhQ&amp;amp;__tn__=R%5d-R&amp;amp;c%5b0%5d=AT3MupuesWeUKBoSG-T0LuyIIzeqWFcyX5I-zYB1VPmXBC2UY-xgyvT9XmhaBEIZfVWwsLaMOq_yNqLx7M0SPxKjHwM8HpJ6R-KLpheQq3QpTau5OYAW6GBzXWWL0GHBxg2awqCyoajmWkviu1WT39E3WO-y6LA4Obo9HCw" target="_blank" rel="noopener"&gt;china.gh.com&lt;/A&gt;","event_type":"Security","src_country_code":"CN","tls_error_description":"unknown CA","action":"Alert","subnet_name":"0.0.0.0/24","pop_name":"china_1","dest_port":443&lt;STRONG&gt;,"&lt;FONT color="#FF0000"&gt;event_sub_type":"TLS&lt;/FONT&gt;","&lt;/STRONG&gt;insertionDate":1701188915580,"dest_country_code":"SG","tls_error_type":"fatal","dns_name":"&lt;A href="http://china.com/?fbclid=IwAR37lD13sfwMF4s4_muvmuPfStg7WrJiISZRREPp40XJwYBb3TQx424Ypoo" target="_blank" rel="noopener"&gt;china.com&lt;/A&gt;","traffic_direction":"OUTBOUND","src_is_site_or_vpn":"Site","account_id":56565,"application":"Netskope","src_site_name":"CHINA-44","src_country":"China","dest_ip":"0.0.0.0","os_type":"OS_WINDOWS","time":1701188836011,"dest_country":"Singapore"}&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 15:47:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670345#M112398</guid>
      <dc:creator>roopeshetty</dc:creator>
      <dc:date>2023-11-30T15:47:05Z</dc:date>
    </item>
    <item>
      <title>Re: props and transform file modification issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670348#M112400</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161725"&gt;@roopeshetty&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;please try this regex in transforms.conf:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;REGEX = \"event_sub_type\":\"(WAN|TLS)&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 15:50:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670348#M112400</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-30T15:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: props and transform file modification issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670363#M112405</link>
      <description>&lt;P&gt;Hi, Tried as below; still no luck , logs are keep coming;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;props.conf&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[sourcetype::cato_source]&lt;BR /&gt;TRANSFORMS-filter_logs = cloudparsing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;transforms.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[cloudparsing]&lt;BR /&gt;REGEX = \"event_sub_type\":\"(WAN|TLS)&lt;BR /&gt;DEST_KEY = queue&lt;BR /&gt;FORMAT = nullQueue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 17:04:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670363#M112405</guid>
      <dc:creator>roopeshetty</dc:creator>
      <dc:date>2023-11-30T17:04:46Z</dc:date>
    </item>
    <item>
      <title>Re: props and transform file modification issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670369#M112408</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161725"&gt;@roopeshetty&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;where did you located props.conf and transforms.conf?&lt;/P&gt;&lt;P&gt;they must be located in the first full Splunk instance that the logs are passing through, in other words in the Indexers or (if present) in the intermediate Heavy Forwarder.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 17:19:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670369#M112408</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-30T17:19:44Z</dc:date>
    </item>
    <item>
      <title>Re: props and transform file modification issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670375#M112409</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;props.conf and transforms.conf are located on our splunk enterprise server on "splunk add on for AWS" app path; that is "&lt;/SPAN&gt;D:\Program Files\Splunk\etc\apps\Splunk_TA_aws\local"&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 17:32:00 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670375#M112409</guid>
      <dc:creator>roopeshetty</dc:creator>
      <dc:date>2023-11-30T17:32:00Z</dc:date>
    </item>
    <item>
      <title>Re: props and transform file modification issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670378#M112410</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161725"&gt;@roopeshetty&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;yes, but where is the input for there data flow: in the same server or in a different Heavy Forwarder?&lt;/P&gt;&lt;P&gt;If in a different Heavy Forwarder, you have to put these props.conf and transforms.conf in it.&lt;/P&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 17:36:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670378#M112410</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-30T17:36:56Z</dc:date>
    </item>
    <item>
      <title>Re: props and transform file modification issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670381#M112411</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&amp;nbsp;&lt;SPAN&gt;input&amp;nbsp;also located on the same server on same path;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 843px;"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/28323iF21764DD09BD8DEE/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 17:42:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670381#M112411</guid>
      <dc:creator>roopeshetty</dc:creator>
      <dc:date>2023-11-30T17:42:20Z</dc:date>
    </item>
    <item>
      <title>Re: props and transform file modification issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670383#M112412</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161725"&gt;@roopeshetty&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;in the header of the props.conf, try to not use "sourcetype:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[cato_source]
TRANSFORMS-filter_logs = cloudparsing&lt;/LI-CODE&gt;&lt;P&gt;Ciao.&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Thu, 30 Nov 2023 17:58:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670383#M112412</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-11-30T17:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: props and transform file modification issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670436#M112421</link>
      <description>&lt;P&gt;Thanks a lot&amp;nbsp;&lt;SPAN&gt;gcusello,&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;It worked as expected. One last question , in below regex we are looking for the texts "WAN" and "TSL"&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;REGEX = \"event_sub_type\":\"(WAN|TLS)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;in case if&amp;nbsp;we want to look for&amp;nbsp; texts "WAN Firewall" and "TSL" , how the regex would be?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 08:53:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670436#M112421</guid>
      <dc:creator>roopeshetty</dc:creator>
      <dc:date>2023-12-01T08:53:57Z</dc:date>
    </item>
    <item>
      <title>Re: props and transform file modification issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670440#M112423</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161725"&gt;@roopeshetty&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;you can use this regex:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;REGEX = \"event_sub_type\":\"((WAN\s+Firewall)|TLS)&lt;/LI-CODE&gt;&lt;P&gt;that you can test at&amp;nbsp;&lt;A href="https://regex101.com/r/YBCWAB/1" target="_blank"&gt;https://regex101.com/r/YBCWAB/1&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 08:59:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670440#M112423</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-12-01T08:59:20Z</dc:date>
    </item>
    <item>
      <title>Re: props and transform file modification issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670447#M112425</link>
      <description>&lt;P&gt;thanks a lot.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 10:49:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670447#M112425</guid>
      <dc:creator>roopeshetty</dc:creator>
      <dc:date>2023-12-01T10:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: props and transform file modification issue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670458#M112428</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/161725"&gt;@roopeshetty&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;good for you, see next time!&lt;/P&gt;&lt;P&gt;Ciao and happy splunking&lt;/P&gt;&lt;P&gt;Giuseppe&lt;/P&gt;&lt;P&gt;P.S.: Karma Points are appreciated &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 13:40:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/props-and-transform-file-modification-issue/m-p/670458#M112428</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2023-12-01T13:40:56Z</dc:date>
    </item>
  </channel>
</rss>

