<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Filtering events from forwarder at indexer in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-events-from-forwarder-at-indexer/m-p/87077#M18072</link>
    <description>&lt;P&gt;Are you sure its a LWF?  If not, the data is already cooked and cannot be manipulated at the indexer.&lt;/P&gt;</description>
    <pubDate>Wed, 10 Nov 2010 14:54:17 GMT</pubDate>
    <dc:creator>the_wolverine</dc:creator>
    <dc:date>2010-11-10T14:54:17Z</dc:date>
    <item>
      <title>Filtering events from forwarder at indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-events-from-forwarder-at-indexer/m-p/87074#M18069</link>
      <description>&lt;P&gt;I'm trying to filter noisy events that have recently pushed us over license usage. The events come from a lightweight forwarder that I don't have access to at the moment. I'd like to filter at the indexer. This is not working:&lt;/P&gt;

&lt;P&gt;props.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[source::/Logs/Noisy.log]
TRANSFORMS-set = setnull
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[setnull]
REGEX = host07
DEST_KEY = queue
FORMAT = nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Where "host07" is present in all the logs I want to dump, and the source matches that displayed in search results on the indexer. I've also tried listing the sourcetype as shown in search results.&lt;/P&gt;

&lt;P&gt;Gotta be something simple... or maybe LWF traffic needs to be filtered on the LWF, not the indexer?&lt;/P&gt;

&lt;P&gt;Thanks,
Jon&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2010 07:45:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-events-from-forwarder-at-indexer/m-p/87074#M18069</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2010-11-10T07:45:46Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering events from forwarder at indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-events-from-forwarder-at-indexer/m-p/87075#M18070</link>
      <description>&lt;P&gt;Lightweight Forwarder &lt;STRONG&gt;requires&lt;/STRONG&gt; filtering to be done at the indexer -- it cannot do it itself.  &lt;/P&gt;

&lt;P&gt;The answer &lt;A href="http://splunk-base.splunk.com/answers/96/how-do-i-exclude-some-events-from-being-indexed-by-splunk" target="test_blank"&gt;http://splunk-base.splunk.com/answers/96/how-do-i-exclude-some-events-from-being-indexed-by-splunk&lt;/A&gt; has some good examples of using nullQueue.  &lt;/P&gt;

&lt;P&gt;At a quick glance, your example looks fundamentally correct.  Does "host07" appear in the _raw for the events in question, or is it in another metadata field?&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2010 11:18:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-events-from-forwarder-at-indexer/m-p/87075#M18070</guid>
      <dc:creator>dwaddle</dc:creator>
      <dc:date>2010-11-10T11:18:08Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering events from forwarder at indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-events-from-forwarder-at-indexer/m-p/87076#M18071</link>
      <description>&lt;P&gt;Yes, the string is in _raw.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2010 12:18:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-events-from-forwarder-at-indexer/m-p/87076#M18071</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2010-11-10T12:18:55Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering events from forwarder at indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-events-from-forwarder-at-indexer/m-p/87077#M18072</link>
      <description>&lt;P&gt;Are you sure its a LWF?  If not, the data is already cooked and cannot be manipulated at the indexer.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2010 14:54:17 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-events-from-forwarder-at-indexer/m-p/87077#M18072</guid>
      <dc:creator>the_wolverine</dc:creator>
      <dc:date>2010-11-10T14:54:17Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering events from forwarder at indexer</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-events-from-forwarder-at-indexer/m-p/87078#M18073</link>
      <description>&lt;P&gt;Is there any way to tell from the indexer's side? I did not do the install, just gave a list of command line instructions. It's possible the server admin didn't follow them.&lt;/P&gt;</description>
      <pubDate>Wed, 10 Nov 2010 22:44:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-events-from-forwarder-at-indexer/m-p/87078#M18073</guid>
      <dc:creator>twinspop</dc:creator>
      <dc:date>2010-11-10T22:44:12Z</dc:date>
    </item>
  </channel>
</rss>

