<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Exclude log rows from journald input in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Exclude-log-rows-from-journald-input/m-p/760887#M120495</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309167"&gt;@jni&lt;/a&gt;&amp;nbsp; &amp;nbsp;May i know if you are using the Heavy Forwarder?&lt;SPAN&gt;The UF is a light weight agent and it got the least features. To filter specific lines while excluding others at the Splunk Universal Forwarder (UF) level, you cannot use typical props.conf line-filtering on the UF itself.&lt;BR /&gt;&lt;BR /&gt;Instead, you must &lt;STRONG&gt;use regex in inputs.conf to filter files or &lt;STRONG&gt;send data to an Indexer/Heavy Forwarder to use transforms.conf to create a nullQueue&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------------------------------------&lt;BR /&gt;If this post or any post addressed your question, could you pls:&lt;BR /&gt;Give it karma to show appreciation&lt;/P&gt;&lt;P&gt;PS - As of May 2026, my Karma Given is 2312 and my Karma Received is 497, lets revamp the Karma Culture!&lt;BR /&gt;Thanks and best regards, Sekar&lt;BR /&gt;--------------------------------------------------------------------------------------------&lt;/P&gt;</description>
    <pubDate>Tue, 12 May 2026 12:13:04 GMT</pubDate>
    <dc:creator>inventsekar</dc:creator>
    <dc:date>2026-05-12T12:13:04Z</dc:date>
    <item>
      <title>Exclude log rows from journald input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Exclude-log-rows-from-journald-input/m-p/760880#M120494</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I'm ingesting journald logdata, and would like to exclude all rows with "apparmor=ALLOW".&lt;/P&gt;&lt;P&gt;To me, the journald-filter parameter would do the trick, if I can invert the selection, i.e. "grep -v"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this possible, or is there another way to do this, without adding everything else to the journald-filter-parameter?&lt;/P&gt;&lt;P&gt;I'm using UF and Enterprise 9.4.1&lt;/P&gt;&lt;P&gt;TIA&lt;/P&gt;&lt;P&gt;Johan Nilsson&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2026 05:46:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Exclude-log-rows-from-journald-input/m-p/760880#M120494</guid>
      <dc:creator>jni</dc:creator>
      <dc:date>2026-05-12T05:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude log rows from journald input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Exclude-log-rows-from-journald-input/m-p/760887#M120495</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309167"&gt;@jni&lt;/a&gt;&amp;nbsp; &amp;nbsp;May i know if you are using the Heavy Forwarder?&lt;SPAN&gt;The UF is a light weight agent and it got the least features. To filter specific lines while excluding others at the Splunk Universal Forwarder (UF) level, you cannot use typical props.conf line-filtering on the UF itself.&lt;BR /&gt;&lt;BR /&gt;Instead, you must &lt;STRONG&gt;use regex in inputs.conf to filter files or &lt;STRONG&gt;send data to an Indexer/Heavy Forwarder to use transforms.conf to create a nullQueue&lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;----------------------------------------------------------------------------------------------&lt;BR /&gt;If this post or any post addressed your question, could you pls:&lt;BR /&gt;Give it karma to show appreciation&lt;/P&gt;&lt;P&gt;PS - As of May 2026, my Karma Given is 2312 and my Karma Received is 497, lets revamp the Karma Culture!&lt;BR /&gt;Thanks and best regards, Sekar&lt;BR /&gt;--------------------------------------------------------------------------------------------&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2026 12:13:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Exclude-log-rows-from-journald-input/m-p/760887#M120495</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2026-05-12T12:13:04Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude log rows from journald input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Exclude-log-rows-from-journald-input/m-p/760888#M120496</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/80737"&gt;@inventsekar&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm using a UF on the client, where I'd like to get rid of the journald log lines.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So, if I understand you correctly : I need to send all journald log-data to the HF/indexer, and there use transforms to drop the lines?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your help!&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Johan&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2026 12:58:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Exclude-log-rows-from-journald-input/m-p/760888#M120496</guid>
      <dc:creator>jni</dc:creator>
      <dc:date>2026-05-12T12:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude log rows from journald input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Exclude-log-rows-from-journald-input/m-p/760889#M120497</link>
      <description>&lt;P&gt;Have you tried this filter?&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;JournalFilter = NOT MESSAGE~"apparmor=ALLOW"&lt;/LI-CODE&gt;&lt;P&gt;If that doesn't work then you can use props and transforms or Ingest Actions to drop the unwanted events in HF or indexer.&amp;nbsp; Props and transforms work only in the first full instance (HF or indexer) that the data passes through; Ingest Actions work in any full instance.&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2026 13:08:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Exclude-log-rows-from-journald-input/m-p/760889#M120497</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2026-05-12T13:08:20Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude log rows from journald input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Exclude-log-rows-from-journald-input/m-p/760890#M120498</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309167"&gt;@jni&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;So, if I understand you correctly : I need to send all journald log-data to the HF/indexer, and there use transforms to drop the lines?&amp;nbsp;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yes, exactly. or you can use inputs.conf on the HF.&lt;BR /&gt;&lt;BR /&gt;to summarize, the two ideas are:&lt;BR /&gt;1) On the HF or Indexer, you can use regex in inputs.conf to filter lines&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;2) send the log to an Indexer/Heavy Forwarder to use props.conf and transforms.conf to create a nullQueue (to drop the selected events)&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2026 13:08:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Exclude-log-rows-from-journald-input/m-p/760890#M120498</guid>
      <dc:creator>inventsekar</dc:creator>
      <dc:date>2026-05-12T13:08:38Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude log rows from journald input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Exclude-log-rows-from-journald-input/m-p/760891#M120499</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/213957"&gt;@richgalloway&lt;/a&gt;&amp;nbsp;!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the suggestion, but that didn't help. I guess regex it is &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks and best regards&lt;/P&gt;&lt;P&gt;Johan&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2026 13:34:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Exclude-log-rows-from-journald-input/m-p/760891#M120499</guid>
      <dc:creator>jni</dc:creator>
      <dc:date>2026-05-12T13:34:12Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude log rows from journald input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Exclude-log-rows-from-journald-input/m-p/760893#M120500</link>
      <description>&lt;P&gt;The option for jounald input is&lt;/P&gt;&lt;PRE&gt;journalctl-filter = &amp;lt;string&amp;gt;
* These settings map directly to the arguments for the journalctl command.
  See the documentation for journalctl.
* Default: none&lt;/PRE&gt;&lt;P&gt;But in this case it might be just&lt;/P&gt;&lt;PRE&gt;journalctl-grep = &amp;lt;string&amp;gt;
* Equivalent to ‘-g’ parameter of journalctl; filter output to entries
  where the MESSAGE= field matches the specified regular expression.
  PERL-compatible regular expressions are used
* Default: none&lt;/PRE&gt;&lt;P&gt;Unfortunately, those options are "inclusive filters", not exclusion ones so it might be tricky since the filters do not support wildcards either (which is frustrating if you want to just include entries which have a specific field set to anything when other events simply do not have this field).&lt;/P&gt;&lt;P&gt;So unfortunately, the only way to go can be indeed to ingest everything with the UF and then filter out on the "heavie". (which of course means that you need to haul a lot of unnecessary data over the network; tough luck).&lt;/P&gt;&lt;P&gt;It's not specific to Splunk's input, it's rather how journalctl works.&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2026 16:21:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Exclude-log-rows-from-journald-input/m-p/760893#M120500</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2026-05-12T16:21:29Z</dc:date>
    </item>
    <item>
      <title>Re: Exclude log rows from journald input</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Exclude-log-rows-from-journald-input/m-p/760899#M120501</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/309167"&gt;@jni&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;On a UF your options are limited as the others have shared, because the journald input configs are inclusive not negative checks, if you dont have a HF or dont want to send this data from the UF then I think the only other thing you could look as is the lesser-well-known 'force_local_processing' flag in props.conf - Note that this makes the UF process a bit like a HF and may increase CPU usage.&lt;/P&gt;&lt;P&gt;For more info check out&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.12/Admin/Propsconf#:~:text=force_local_processing" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.2.12/Admin/Propsconf#:~:text=force_local_processing&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Example config:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;## props.conf ##

[yourSourcetype]
force_local_processing = true
TRANSFORMS-drop_apparmor = drop_apparmor_allow

## transforms.conf ##
[drop_apparmor_allow]
REGEX = apparmor=ALLOWED
DEST_KEY = queue
FORMAT = nullQueue&lt;/LI-CODE&gt;&lt;P&gt;&lt;span class="lia-unicode-emoji" title=":glowing_star:"&gt;🌟&lt;/span&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;Did this answer help you?&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If so, please consider:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Adding karma to show it was useful&lt;/LI&gt;&lt;LI&gt;Marking it as the solution if it resolved your issue&lt;/LI&gt;&lt;LI&gt;Commenting if you need any clarification&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Your feedback encourages the volunteers in this community to continue contributing&lt;/P&gt;</description>
      <pubDate>Tue, 12 May 2026 17:26:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Exclude-log-rows-from-journald-input/m-p/760899#M120501</guid>
      <dc:creator>livehybrid</dc:creator>
      <dc:date>2026-05-12T17:26:43Z</dc:date>
    </item>
  </channel>
</rss>

