<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Stop splunk processing ? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68692#M13910</link>
    <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;So to make this very clear for everybody &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Putting this into the props.conf on the UF is useless as the sourcetype will not be assigned ?&lt;BR /&gt;
Will the BREAK_ONLY_BEFORE stuff be evaluated ? &lt;BR /&gt;
It looks like it is for me (version 4.3.4 build 136012.) but I need to do the same on the indexer ?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[source::/boot/...]
BREAK_ONLY_BEFORE_DATE=false
BREAK_ONLY_BEFORE=goblygook
LEARN_MODEL = false
LEARN_SOURCETYPE = false
MAX_EVENTS=200000
sourcetype=os_files
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Mon, 28 Sep 2020 13:04:19 GMT</pubDate>
    <dc:creator>flo_cognosec</dc:creator>
    <dc:date>2020-09-28T13:04:19Z</dc:date>
    <item>
      <title>Stop splunk processing ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68687#M13905</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;I might get things wrong, but for now I have the following problem / setup&lt;/P&gt;

&lt;P&gt;forwarder with some files in some directories monitored by fschange defined in inputs.conf&lt;BR /&gt;
some processing options in props.conf (I would like to stop processing here as all has been done)&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;BLOCKQUOTE&gt;
&lt;P&gt;stuff gets sent to the indexer&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/BLOCKQUOTE&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;now the issue is that splunk does start to parse the events again on the indexes and does indeed se-set some of my options.&lt;/P&gt;

&lt;P&gt;So is it a good idea to do some parsing on the forwarder or is it possible to tell splunk to stop processing some events and just take what is coming in from the forwarder ?&lt;/P&gt;

&lt;P&gt;Should I do all the processing on the indexer and only keep an inputs.conf on the forwarder and drop the props.conf ?&lt;/P&gt;

&lt;P&gt;Side-question: if I set the sourcetype in inputs.conf, which events does this effectively affect when using some fschange stanza ?&lt;/P&gt;</description>
      <pubDate>Wed, 19 Dec 2012 14:57:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68687#M13905</guid>
      <dc:creator>flo_cognosec</dc:creator>
      <dc:date>2012-12-19T14:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: Stop splunk processing ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68688#M13906</link>
      <description>&lt;P&gt;No ideas or was the question phrased wrong ?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2013 10:59:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68688#M13906</guid>
      <dc:creator>flo_cognosec</dc:creator>
      <dc:date>2013-01-09T10:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: Stop splunk processing ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68689#M13907</link>
      <description>&lt;P&gt;Are you sure any parsing is actually being done on the forwarder? If you are using a Universal or Light forwarder then they don't actually do any parsing, the parsing is all handled by the indexer so what you may be experiencing is actually the normal behaviour, even if it isn't what you expected &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Define all your parsing requirements at the indexer. Just define your inputs.conf on the universal forwarder and let the indexer handle the rest.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2013 11:25:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68689#M13907</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2013-01-09T11:25:44Z</dc:date>
    </item>
    <item>
      <title>Re: Stop splunk processing ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68690#M13908</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;Actually some parsing IS done on the UF, there was a document explaining it but I can't find it anymore or maybe the changed that &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Thanks anyway &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2013 11:28:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68690#M13908</guid>
      <dc:creator>flo_cognosec</dc:creator>
      <dc:date>2013-01-09T11:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: Stop splunk processing ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68691#M13909</link>
      <description>&lt;P&gt;No, parsing isn't handled on the UF. I've got the internal queue doc here listing its processes. It does have a parsing queue for windows events but thats a special exception. The only props configurations it will handle are for CHARSET, NO_BINARY_CHECK,CHECK_METHOD and CHECK_FOR_HEADER (depreciated in v5).&lt;BR /&gt;
EDIT: From the public docs, &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Introducingtheuniversalforwarder" target="_blank"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Introducingtheuniversalforwarder&lt;/A&gt;.&lt;BR /&gt;
&lt;CODE&gt;The universal forwarder does not parse data.&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:04:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68691#M13909</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2020-09-28T13:04:10Z</dc:date>
    </item>
    <item>
      <title>Re: Stop splunk processing ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68692#M13910</link>
      <description>&lt;P&gt;Hi &lt;/P&gt;

&lt;P&gt;So to make this very clear for everybody &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Putting this into the props.conf on the UF is useless as the sourcetype will not be assigned ?&lt;BR /&gt;
Will the BREAK_ONLY_BEFORE stuff be evaluated ? &lt;BR /&gt;
It looks like it is for me (version 4.3.4 build 136012.) but I need to do the same on the indexer ?&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[source::/boot/...]
BREAK_ONLY_BEFORE_DATE=false
BREAK_ONLY_BEFORE=goblygook
LEARN_MODEL = false
LEARN_SOURCETYPE = false
MAX_EVENTS=200000
sourcetype=os_files
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:04:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68692#M13910</guid>
      <dc:creator>flo_cognosec</dc:creator>
      <dc:date>2020-09-28T13:04:19Z</dc:date>
    </item>
    <item>
      <title>Re: Stop splunk processing ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68693#M13911</link>
      <description>&lt;P&gt;You would set the sourcetype in the inputs.conf and then reference the sourcetype in the props on the indexer to handle the linebreaking.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Jan 2013 13:04:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68693#M13911</guid>
      <dc:creator>Drainy</dc:creator>
      <dc:date>2013-01-09T13:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: Stop splunk processing ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68694#M13912</link>
      <description>&lt;P&gt;What should be noted somewhere is the fact that assigning a sourcetype in inputs.conf AND using fschange stanza only means you can assign a sourcetype to this "kind" of event:&lt;/P&gt;

&lt;P&gt;Wed Jan  9 18:22:00 2013 action=add, path="/sbin/bla_false.txt", isdir=0, size=66359, gid=0, uid=0, modtime="Wed Jan  9 18:19:55 2013", mode="rw-r--r--", hash=Bm8/v+HakIJOvaUvaEbn7ofqDHBh3VUs673BHCxaU6f= host=10.0.0.1&lt;BR /&gt;
sourcetype=tmp_files&lt;BR /&gt;
source=fschangemonitor &lt;BR /&gt;
path=/sbin/bla_false.txt&lt;BR /&gt;
action=add&lt;/P&gt;

&lt;P&gt;but NOT to the event containing the file content itself.&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 13:04:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68694#M13912</guid>
      <dc:creator>flo_cognosec</dc:creator>
      <dc:date>2020-09-28T13:04:30Z</dc:date>
    </item>
    <item>
      <title>Re: Stop splunk processing ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68695#M13913</link>
      <description>&lt;P&gt;Somehow the problem still exists.&lt;/P&gt;

&lt;P&gt;Just assigning the sourcetype in the fschange stanza in inputs.conf and then on the indexer try to do some parsing in props.conf does NOT work in a useful way as described above.&lt;BR /&gt;
(short: the file change event will get the correct sourcetype, the file content event not)&lt;/P&gt;

&lt;P&gt;Testing shows that I need to assign the sourcetype in a source:: stanza on the UF in props.conf as well as assiging this on the indexer in props.conf did NOT work &lt;span class="lia-unicode-emoji" title=":confused_face:"&gt;😕&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;Where is this exactly documented and why isn't this working as one might expect ?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2013 10:54:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68695#M13913</guid>
      <dc:creator>flo_cognosec</dc:creator>
      <dc:date>2013-01-23T10:54:41Z</dc:date>
    </item>
    <item>
      <title>Re: Stop splunk processing ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68696#M13914</link>
      <description>&lt;P&gt;It somehow contradicts this wiki page&lt;/P&gt;

&lt;P&gt;&lt;A href="http://wiki.splunk.com/Deploy:HowToSetupFschange"&gt;http://wiki.splunk.com/Deploy:HowToSetupFschange&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;If this page is wrong, maybe you are able to update it based on the most recent splunk docs.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jan 2013 12:35:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68696#M13914</guid>
      <dc:creator>flo_cognosec</dc:creator>
      <dc:date>2013-01-23T12:35:52Z</dc:date>
    </item>
    <item>
      <title>Re: Stop splunk processing ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68697#M13915</link>
      <description>&lt;P&gt;Interesting enough this wiki page has not been changed and it still seems I have to assign sourcetypes in both the inputs.conf and the props.conf on the UF to catch all the information I need (file content AND the file / change metainformation) (so the wiki page actually seems to be correct)&lt;/P&gt;</description>
      <pubDate>Fri, 17 May 2013 12:58:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Stop-splunk-processing/m-p/68697#M13915</guid>
      <dc:creator>flo_cognosec</dc:creator>
      <dc:date>2013-05-17T12:58:40Z</dc:date>
    </item>
  </channel>
</rss>

