<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Newbie Question on nullQueue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Newbie-Question-on-nullQueue/m-p/67344#M13537</link>
    <description>&lt;P&gt;Thank you for taking an interest.&lt;/P&gt;

&lt;P&gt;We are using universal forwarders on the windows boxes to send the information back to a Linux ran Splunk instance.  I believe that means we are not going wmi (since the splunk server isn't pulling the logs itself).  Do you know what I should use in its place?  I was also under the impression that universal forwarders cannot do this filter themselves, but my boss was potentially told something else?&lt;/P&gt;

&lt;P&gt;Single server Splunk at this time (ignoring the universal forwarders).&lt;/P&gt;</description>
    <pubDate>Fri, 21 Jun 2013 14:34:48 GMT</pubDate>
    <dc:creator>millerjc123</dc:creator>
    <dc:date>2013-06-21T14:34:48Z</dc:date>
    <item>
      <title>Newbie Question on nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Newbie-Question-on-nullQueue/m-p/67342#M13535</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;

&lt;P&gt;I know there are questions similar to mine, but I cannot seem to transform them into a solution for my problem.  I am trying to dump information event logs to the nullQueue so they do not count against the cap (company still deciding if they want Splunk).  What I currently have is (sorry if new lines are messed up):&lt;/P&gt;

&lt;P&gt;transforms.conf:&lt;/P&gt;

&lt;P&gt;[RemoveInformation]&lt;/P&gt;

&lt;P&gt;REGEX=(?m)Type\s*=\s*Information&lt;/P&gt;

&lt;P&gt;DEST_KEY = queue&lt;/P&gt;

&lt;P&gt;FORMAT = nullQueue&lt;/P&gt;

&lt;P&gt;props.conf:&lt;/P&gt;

&lt;P&gt;[WMI:WinEventLog:Application]&lt;/P&gt;

&lt;P&gt;TRANSFORMS-wmi= RemoveInformation&lt;/P&gt;

&lt;P&gt;[WMI:WinEventLog:Security]&lt;/P&gt;

&lt;P&gt;TRANSFORMS-wmi= RemoveInformation&lt;/P&gt;

&lt;P&gt;[WMI:WinEventLog:System]&lt;/P&gt;

&lt;P&gt;TRANSFORMS-wmi= RemoveInformation&lt;/P&gt;

&lt;P&gt;[WMI:WinEventLog:Setup]&lt;/P&gt;

&lt;P&gt;TRANSFORMS-wmi= RemoveInformation&lt;/P&gt;

&lt;P&gt;I don't believe it matters, but I am using windows based universal forwarder back to a debian based splunk server.&lt;/P&gt;

&lt;P&gt;Thank you for any and all suggestions.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:07:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Newbie-Question-on-nullQueue/m-p/67342#M13535</guid>
      <dc:creator>millerjc123</dc:creator>
      <dc:date>2020-09-28T14:07:35Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie Question on nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Newbie-Question-on-nullQueue/m-p/67343#M13536</link>
      <description>&lt;P&gt;A couple of questions. Are you collecting the logs via wmi? If not then the soucetypes will technically be different and not apply your null queue transform. Next question. Are you using dedicated indexers? If so anything with TRANSFORMS is an index time action and that config must be on each of your indexers not your search head to work.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2013 14:04:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Newbie-Question-on-nullQueue/m-p/67343#M13536</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2013-06-21T14:04:32Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie Question on nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Newbie-Question-on-nullQueue/m-p/67344#M13537</link>
      <description>&lt;P&gt;Thank you for taking an interest.&lt;/P&gt;

&lt;P&gt;We are using universal forwarders on the windows boxes to send the information back to a Linux ran Splunk instance.  I believe that means we are not going wmi (since the splunk server isn't pulling the logs itself).  Do you know what I should use in its place?  I was also under the impression that universal forwarders cannot do this filter themselves, but my boss was potentially told something else?&lt;/P&gt;

&lt;P&gt;Single server Splunk at this time (ignoring the universal forwarders).&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2013 14:34:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Newbie-Question-on-nullQueue/m-p/67344#M13537</guid>
      <dc:creator>millerjc123</dc:creator>
      <dc:date>2013-06-21T14:34:48Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie Question on nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Newbie-Question-on-nullQueue/m-p/67345#M13538</link>
      <description>&lt;P&gt;How are you telling the splunk forwarder to pickup the windows logs? Are you using the Windows TA? Or did you create your own inputs.conf?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Jun 2013 15:10:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Newbie-Question-on-nullQueue/m-p/67345#M13538</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2013-06-21T15:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie Question on nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Newbie-Question-on-nullQueue/m-p/67346#M13539</link>
      <description>&lt;P&gt;We originally turned them off since it set off the daily limit.  We now have (in C:\Program Files\SplunkUniversalForwarder\etc\system\local\inputs.conf):&lt;/P&gt;

&lt;P&gt;[WinEventLog:Application]&lt;BR /&gt;
disabled = 0 &lt;BR /&gt;
[WinEventLog:Security]&lt;BR /&gt;
disabled = 0 &lt;BR /&gt;
[WinEventLog:System]&lt;BR /&gt;
disabled = 0 &lt;BR /&gt;
[WinEventLog:Setup]&lt;BR /&gt;
disabled = 0 &lt;/P&gt;

&lt;H1&gt;Enable &lt;COMPANYNAME&gt; Service Logs&lt;/COMPANYNAME&gt;&lt;/H1&gt;

&lt;P&gt;[WinEventLog:&lt;COMPANYNAME&gt;]&lt;BR /&gt;
disabled = 0&lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 0&lt;BR /&gt;
[WinEventLog:&lt;COMPANYNAME&gt; Services]&lt;BR /&gt;
disabled = 0 &lt;BR /&gt;
start_from = oldest&lt;BR /&gt;
current_only = 0&lt;/COMPANYNAME&gt;&lt;/COMPANYNAME&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 14:09:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Newbie-Question-on-nullQueue/m-p/67346#M13539</guid>
      <dc:creator>millerjc123</dc:creator>
      <dc:date>2020-09-28T14:09:02Z</dc:date>
    </item>
    <item>
      <title>Re: Newbie Question on nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Newbie-Question-on-nullQueue/m-p/67347#M13540</link>
      <description>&lt;P&gt;There there is why it is not applying the regex. You have to match the sourcetype.&lt;BR /&gt;
[WMI:WinEventLog:Security]&lt;BR /&gt;
TRANSFORMS-wmi= RemoveInformation&lt;/P&gt;

&lt;P&gt;Needs to be&lt;BR /&gt;
[WinEventLog:Security]&lt;BR /&gt;
TRANSFORMS-WinSecRemove= RemoveInformation&lt;/P&gt;</description>
      <pubDate>Sat, 22 Jun 2013 00:02:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Newbie-Question-on-nullQueue/m-p/67347#M13540</guid>
      <dc:creator>starcher</dc:creator>
      <dc:date>2013-06-22T00:02:17Z</dc:date>
    </item>
  </channel>
</rss>

