<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: drop specific eventcode for specific destination in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/drop-specific-eventcode-for-specific-destination/m-p/752731#M119501</link>
    <description>&lt;P class="lia-align-left"&gt;okay thanks, but we have 2 syslog destinations in this intermediate HF ..both syslogNG's destination key configured as _syslog_routing&lt;BR /&gt;Need to block the specific windows event code in one syslogNG and need to forward that eventcode in another syslogNG ..&lt;BR /&gt;for both syslogNG destinations , configured in different output group in outputs.conf&lt;/P&gt;</description>
    <pubDate>Fri, 05 Sep 2025 06:44:39 GMT</pubDate>
    <dc:creator>Raghavsri</dc:creator>
    <dc:date>2025-09-05T06:44:39Z</dc:date>
    <item>
      <title>drop specific eventcode for specific destination</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/drop-specific-eventcode-for-specific-destination/m-p/752724#M119498</link>
      <description>&lt;P&gt;we have one HF , configured to routing into 3 destinations&amp;nbsp;&lt;/P&gt;&lt;P&gt;2 * syslogNG&lt;/P&gt;&lt;P&gt;1* Splunk HF cluster&lt;/P&gt;&lt;P&gt;our requirement is to drop the specific eventcode 33205 from windows logs , to the one syslogNG destination .. but the same eventcode, need to be recieved by another syslogNG and splunk HF cluster .&lt;BR /&gt;when I try to configure, it drop the eventcode for all destinations if i use below entries&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Props.conf&lt;/P&gt;&lt;P&gt;[source::WinEventLog:Application]&lt;BR /&gt;TRANSFORMS-routing = drop_sqld&lt;/P&gt;&lt;P&gt;Transforms.conf&lt;/P&gt;&lt;P&gt;[drop_sqld]&lt;BR /&gt;REGEX = (?i)EventCode=33205&lt;BR /&gt;DEST_KEY = _raw&lt;BR /&gt;FORMAT = nullQueue&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;can you help on this possiblity ?&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2025 03:23:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/drop-specific-eventcode-for-specific-destination/m-p/752724#M119498</guid>
      <dc:creator>Raghavsri</dc:creator>
      <dc:date>2025-09-05T03:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: drop specific eventcode for specific destination</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/drop-specific-eventcode-for-specific-destination/m-p/752730#M119500</link>
      <description>&lt;P&gt;You need to manipulate the _SYSLOG_ROUTING key, not queue (and definitely not _raw!)&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2025 06:35:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/drop-specific-eventcode-for-specific-destination/m-p/752730#M119500</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2025-09-05T06:35:22Z</dc:date>
    </item>
    <item>
      <title>Re: drop specific eventcode for specific destination</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/drop-specific-eventcode-for-specific-destination/m-p/752731#M119501</link>
      <description>&lt;P class="lia-align-left"&gt;okay thanks, but we have 2 syslog destinations in this intermediate HF ..both syslogNG's destination key configured as _syslog_routing&lt;BR /&gt;Need to block the specific windows event code in one syslogNG and need to forward that eventcode in another syslogNG ..&lt;BR /&gt;for both syslogNG destinations , configured in different output group in outputs.conf&lt;/P&gt;</description>
      <pubDate>Fri, 05 Sep 2025 06:44:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/drop-specific-eventcode-for-specific-destination/m-p/752731#M119501</guid>
      <dc:creator>Raghavsri</dc:creator>
      <dc:date>2025-09-05T06:44:39Z</dc:date>
    </item>
  </channel>
</rss>

