<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Remove events to avoid delayed logging? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Remove-events-to-avoid-delayed-logging/m-p/140870#M28850</link>
    <description>&lt;P&gt;If those cases really are rare you can use the &lt;CODE&gt;delete&lt;/CODE&gt; command to selectively mark events as deleted. That won't clear up space, and isn't recommended for frequent use.&lt;/P&gt;</description>
    <pubDate>Mon, 14 Jul 2014 09:18:36 GMT</pubDate>
    <dc:creator>martin_mueller</dc:creator>
    <dc:date>2014-07-14T09:18:36Z</dc:date>
    <item>
      <title>Remove events to avoid delayed logging?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Remove-events-to-avoid-delayed-logging/m-p/140869#M28849</link>
      <description>&lt;P&gt;Our generated logs need to be verified for correctness. After verification, they are sent to splunk. &lt;/P&gt;

&lt;P&gt;Problem is the verification happens some hours after the logs are generated. This means they are sent to splunk hours after they are created (ie logs appear delayed, not in real time).&lt;/P&gt;

&lt;P&gt;In 99.9999% of all cases, logs are verified ok which means this delay not needed.&lt;/P&gt;

&lt;P&gt;Is there a way around this? My naive idea is to have splunk pick up the unverified logs immediately, and then (hours later) when they are verified confirm them in splunk or delete/mark/evict invalid logs from the index.&lt;/P&gt;

&lt;P&gt;Is this possible or can I use some other approach?&lt;/P&gt;

&lt;P&gt;/Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2014 09:08:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Remove-events-to-avoid-delayed-logging/m-p/140869#M28849</guid>
      <dc:creator>wickman</dc:creator>
      <dc:date>2014-07-14T09:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: Remove events to avoid delayed logging?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Remove-events-to-avoid-delayed-logging/m-p/140870#M28850</link>
      <description>&lt;P&gt;If those cases really are rare you can use the &lt;CODE&gt;delete&lt;/CODE&gt; command to selectively mark events as deleted. That won't clear up space, and isn't recommended for frequent use.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2014 09:18:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Remove-events-to-avoid-delayed-logging/m-p/140870#M28850</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-07-14T09:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: Remove events to avoid delayed logging?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Remove-events-to-avoid-delayed-logging/m-p/140871#M28851</link>
      <description>&lt;P&gt;Is it possible to script the &lt;CODE&gt;delete&lt;/CODE&gt; command remotely? I'm thinking the verifier could do that automatically when it detects an invalid log?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jul 2014 09:21:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Remove-events-to-avoid-delayed-logging/m-p/140871#M28851</guid>
      <dc:creator>wickman</dc:creator>
      <dc:date>2014-07-14T09:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: Remove events to avoid delayed logging?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Remove-events-to-avoid-delayed-logging/m-p/140872#M28852</link>
      <description>&lt;P&gt;Sure, you can start any search job remotely via the REST API or one of the SDKs available at &lt;A href="http://dev.splunk.com/"&gt;http://dev.splunk.com/&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Jul 2014 10:28:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Remove-events-to-avoid-delayed-logging/m-p/140872#M28852</guid>
      <dc:creator>martin_mueller</dc:creator>
      <dc:date>2014-07-17T10:28:05Z</dc:date>
    </item>
  </channel>
</rss>

