<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Filter portions of multi-line logs using a Heavy Forwarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Filter-portions-of-multi-line-logs-using-a-Heavy-Forwarder/m-p/192301#M38365</link>
    <description>&lt;P&gt;Any ideas?&lt;/P&gt;</description>
    <pubDate>Tue, 24 Mar 2015 15:41:15 GMT</pubDate>
    <dc:creator>Raghav2384</dc:creator>
    <dc:date>2015-03-24T15:41:15Z</dc:date>
    <item>
      <title>Filter portions of multi-line logs using a Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-portions-of-multi-line-logs-using-a-Heavy-Forwarder/m-p/192300#M38364</link>
      <description>&lt;P&gt;Hello Experts, I had posted the same question couple of days ago and had to re-post because of the formatting issues. We are consuming certain logs with DEBUG level but realized only a portion of those we need to index. We have decided to extract those required portions and discard rest of the stuff. These are logs averaging 50 lines per event. I just want to make sure we do it right the first time as the usage is pretty deep and do not want to interrupt. Here's a sample log&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;172.18.232.85 [2015-03-04 15:20:25,083] ===============================================&lt;BR /&gt;
POLICY RESULT ERROR: Unable to authorize session - no authorization result found&lt;BR /&gt;
Key1 = value1&lt;BR /&gt;
Key2 = Value2&lt;BR /&gt;
Key3 = Value3&lt;BR /&gt;
Key4 = Value4&lt;BR /&gt;
Key5 = Value5&lt;BR /&gt;
Key6 = Value6&lt;BR /&gt;
Key7 = Value7&lt;BR /&gt;
Key8 = Value8&lt;BR /&gt;
Key9 = Value9&lt;BR /&gt;
DEBUG MSGS:&lt;/STRONG&gt;&lt;BR /&gt;
        INFO   : (core) Tagging message with ID: &lt;STRONG&gt;Important Stuff here&lt;/STRONG&gt;&lt;BR /&gt;
        INFO   : (radius) RADIUS device group &lt;STRONG&gt;assigned to: Phoenix&lt;/STRONG&gt;&lt;BR /&gt;
        INFO   : (radius) Loading session by the audit &lt;STRONG&gt;session id: XYZ&lt;/STRONG&gt;&lt;BR /&gt;
        INFO   : (core) Lock obtained on key: &lt;STRONG&gt;auditSessionId:ab1234bcngd&lt;/STRONG&gt;&lt;BR /&gt;
        INFO   : (core) Start session triggered&lt;BR /&gt;
        INFO   : (radius) Radius usage reported 123456&lt;BR /&gt;
        INFO   : (radius) Found generic location parameter &lt;STRONG&gt;ssid/DomainID&lt;/STRONG&gt;&lt;BR /&gt;
        INFO   : (radius) Found generic location parameter &lt;STRONG&gt;ap_mac/12-23-45-67-89&lt;/STRONG&gt;&lt;BR /&gt;
        INFO   : (location) Using generic ssid\XYZABC for location lookup.&lt;BR /&gt;
        INFO   : (location) Using generic ap_mac\12-23-45-67-89 for location lookup.&lt;BR /&gt;
        INFO   : (location) Location found for generic matching: ssid\DomainID&lt;BR /&gt;
        WARN   : (auth) Failed USUM_AUTHORIZATION no password found for user&lt;BR /&gt;
        WARN   : (core) Removing session since no authorization result found&lt;BR /&gt;
        WARN   : (service) Stopping creation since the session has no services&lt;BR /&gt;
        INFO   : (balance) Error found,  rolling back transaction&lt;/P&gt;

&lt;H1&gt;        ERROR  : &lt;STRONG&gt;(core) Error processing policy request: Unable to authorize session - no authorization result found&lt;/STRONG&gt;&lt;/H1&gt;

&lt;P&gt;we do not want to index entire Debug...I just need to grab the fields/Text in Bold and send rest to the null Queue. All of these are multiline logs and i am not able to get close in achieving this. Appreciate any pointers&lt;/P&gt;

&lt;P&gt;Thanks,&lt;BR /&gt;
Raghav&lt;/P&gt;</description>
      <pubDate>Mon, 28 Sep 2020 19:16:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-portions-of-multi-line-logs-using-a-Heavy-Forwarder/m-p/192300#M38364</guid>
      <dc:creator>Raghav2384</dc:creator>
      <dc:date>2020-09-28T19:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: Filter portions of multi-line logs using a Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-portions-of-multi-line-logs-using-a-Heavy-Forwarder/m-p/192301#M38365</link>
      <description>&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2015 15:41:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-portions-of-multi-line-logs-using-a-Heavy-Forwarder/m-p/192301#M38365</guid>
      <dc:creator>Raghav2384</dc:creator>
      <dc:date>2015-03-24T15:41:15Z</dc:date>
    </item>
    <item>
      <title>Re: Filter portions of multi-line logs using a Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-portions-of-multi-line-logs-using-a-Heavy-Forwarder/m-p/192302#M38366</link>
      <description>&lt;P&gt;Is the format of the logs always same?? We need to identify patterns for which lines to retain and which lines to discard.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2015 16:38:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-portions-of-multi-line-logs-using-a-Heavy-Forwarder/m-p/192302#M38366</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-03-24T16:38:21Z</dc:date>
    </item>
    <item>
      <title>Re: Filter portions of multi-line logs using a Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-portions-of-multi-line-logs-using-a-Heavy-Forwarder/m-p/192303#M38367</link>
      <description>&lt;P&gt;Yes, standard is, the pieces i want from debug portion remains same&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2015 16:59:43 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-portions-of-multi-line-logs-using-a-Heavy-Forwarder/m-p/192303#M38367</guid>
      <dc:creator>Raghav2384</dc:creator>
      <dc:date>2015-03-24T16:59:43Z</dc:date>
    </item>
    <item>
      <title>Re: Filter portions of multi-line logs using a Heavy Forwarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filter-portions-of-multi-line-logs-using-a-Heavy-Forwarder/m-p/192304#M38368</link>
      <description>&lt;P&gt;You can do it like this in your &lt;CODE&gt;props.conf&lt;/CODE&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[MyBigFatSourcetype]
SEDCMD-slimfast = s/^INFO : (core) Start.*$// s/^INFO : (radius) Radius.*$// s/^INFO : (location).*$// s/^WARN :.*$// s/^INFO : (balance).*$//
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;This will definitely work but the downside is that, although the text will definitely be gone, I think it will leave blank line gaps in the raw events which may be distracting/confusing.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Aug 2015 22:58:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filter-portions-of-multi-line-logs-using-a-Heavy-Forwarder/m-p/192304#M38368</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-08-11T22:58:51Z</dc:date>
    </item>
  </channel>
</rss>

