<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can I enable filtering on a Splunk Light Forwarder? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100292#M20992</link>
    <description>&lt;P&gt;Well I decided to the the filtering from the Splunk SearchHead/indexer side, passing the logs through using a Splunk Light Forwarder.&lt;/P&gt;

&lt;P&gt;Ill leave this question as a reference for others who may search for the same questions.&lt;/P&gt;

&lt;P&gt;Thanks anyways Splunkers&lt;/P&gt;</description>
    <pubDate>Wed, 24 Oct 2012 23:52:26 GMT</pubDate>
    <dc:creator>Dark_Ichigo</dc:creator>
    <dc:date>2012-10-24T23:52:26Z</dc:date>
    <item>
      <title>Can I enable filtering on a Splunk Light Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100283#M20983</link>
      <description>&lt;P&gt;All I want to do is to use the filtering functionality on the Splunk Light Forwarder without having to enable the Heavy Forwarder, as most features are disabled in the Splunk Light Forwarder as stated here: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Forwardercapabilities"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Forwardercapabilities&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;I would still like to use the Splunk Light Forwarder but enable the filtering feature only, Can this be done, if so then how?&lt;/P&gt;

&lt;P&gt;I do recall that there was a way to enable this on a Splunk Light Forwarder, as this functionality is actually disabled and not removed, so enabling it should be possible. &lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2012 02:34:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100283#M20983</guid>
      <dc:creator>Dark_Ichigo</dc:creator>
      <dc:date>2012-10-24T02:34:32Z</dc:date>
    </item>
    <item>
      <title>Re: Can I enable filtering on a Splunk Light Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100284#M20984</link>
      <description>&lt;P&gt;Nope, if you use the Light Forwarder, you cannot enable filtering. Filtering requires parsing and parsing requires a heavy forwarder.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2012 03:16:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100284#M20984</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-10-24T03:16:52Z</dc:date>
    </item>
    <item>
      <title>Re: Can I enable filtering on a Splunk Light Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100285#M20985</link>
      <description>&lt;P&gt;But I was told that all I have to do is create a props.conf file under /system/local and Im all set for when I start the forwarding, so its simply just enabling that extra feature?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2012 03:27:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100285#M20985</guid>
      <dc:creator>Dark_Ichigo</dc:creator>
      <dc:date>2012-10-24T03:27:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can I enable filtering on a Splunk Light Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100286#M20986</link>
      <description>&lt;P&gt;No. Those settings will just be ignored.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2012 03:36:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100286#M20986</guid>
      <dc:creator>gkanapathy</dc:creator>
      <dc:date>2012-10-24T03:36:34Z</dc:date>
    </item>
    <item>
      <title>Re: Can I enable filtering on a Splunk Light Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100287#M20987</link>
      <description>&lt;P&gt;So your saying there is absolutely no way to enable filtering on a Splunk Light Forwarder at all?, cause its just disabled and not removed, so Im sure there is a way to enable this disabled functionality.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2012 04:09:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100287#M20987</guid>
      <dc:creator>Dark_Ichigo</dc:creator>
      <dc:date>2012-10-24T04:09:50Z</dc:date>
    </item>
    <item>
      <title>Re: Can I enable filtering on a Splunk Light Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100288#M20988</link>
      <description>&lt;P&gt;one could enable parsing again, but then it is no longer a light forwarder &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2012 05:50:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100288#M20988</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2012-10-24T05:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: Can I enable filtering on a Splunk Light Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100289#M20989</link>
      <description>&lt;P&gt;true, but indexing and all the other functionalists would be turned off, so I would just have this extra function, we can call it a Light Heavy forwarder??&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2012 06:22:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100289#M20989</guid>
      <dc:creator>Dark_Ichigo</dc:creator>
      <dc:date>2012-10-24T06:22:09Z</dc:date>
    </item>
    <item>
      <title>Re: Can I enable filtering on a Splunk Light Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100290#M20990</link>
      <description>&lt;P&gt;Question is though, how would I be able to enable it?&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2012 06:22:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100290#M20990</guid>
      <dc:creator>Dark_Ichigo</dc:creator>
      <dc:date>2012-10-24T06:22:31Z</dc:date>
    </item>
    <item>
      <title>Re: Can I enable filtering on a Splunk Light Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100291#M20991</link>
      <description>&lt;P&gt;Sorry, you are wrong. You can't do it. It's not an option. There is no way to enable it, unless as MuS says, you enable parsing again. Then it becomes a heavy forwarder.&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2012 13:07:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100291#M20991</guid>
      <dc:creator>lguinn2</dc:creator>
      <dc:date>2012-10-24T13:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: Can I enable filtering on a Splunk Light Forwarder?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100292#M20992</link>
      <description>&lt;P&gt;Well I decided to the the filtering from the Splunk SearchHead/indexer side, passing the logs through using a Splunk Light Forwarder.&lt;/P&gt;

&lt;P&gt;Ill leave this question as a reference for others who may search for the same questions.&lt;/P&gt;

&lt;P&gt;Thanks anyways Splunkers&lt;/P&gt;</description>
      <pubDate>Wed, 24 Oct 2012 23:52:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Can-I-enable-filtering-on-a-Splunk-Light-Forwarder/m-p/100292#M20992</guid>
      <dc:creator>Dark_Ichigo</dc:creator>
      <dc:date>2012-10-24T23:52:26Z</dc:date>
    </item>
  </channel>
</rss>

