<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do I edit my props.conf and transforms.conf to filter select events from one source file from getting indexed? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206856#M40829</link>
    <description>&lt;P&gt;Yes, its Windows Server 2012.&lt;/P&gt;

&lt;P&gt;bfnpmsz&lt;/P&gt;</description>
    <pubDate>Thu, 29 Oct 2015 17:30:09 GMT</pubDate>
    <dc:creator>bfnpmsz</dc:creator>
    <dc:date>2015-10-29T17:30:09Z</dc:date>
    <item>
      <title>How do I edit my props.conf and transforms.conf to filter select events from one source file from getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206847#M40820</link>
      <description>&lt;P&gt;We have a vanilla install, just one stand alone Splunk Server.  I am wanting to filter select events from one source file.  Not sure how to do it.&lt;/P&gt;

&lt;P&gt;I have attempted to research the solution, but nothing so far has worked as expected.  Maybe my expectations are not what they should be.  &lt;/P&gt;

&lt;P&gt;Here is my props.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[source::"\\\\Alvionix03\\d\\InCharge\\SAM\\smarts\\local\\logs\\TRAPS-Proview.log"]
TRANSFORMS-null= discards
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Here is my transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[discards]
REGEX = Discard:\s+'YES'
DEST_KEY = queue
FORMAT = nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;My expectations are that all the records which are marked as discarded in our log will not be indexed.&lt;BR /&gt;
Example of one record of my data:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;======================== Trap attributes =========================
Timestamp:           'October 27, 2015 10:54:16 AM CDT'
Agent:               '10.10.54.82'
Enterprise OID:      '.1.3.6.1.4.1.14760'
Generic Type:        '6'
Specific Type:       '1'
Varbinds:            [oid]-&amp;gt;[varbind]
                     '.1.3.6.1.4.1.14760.2.1.2.1' --&amp;gt; 'A362-2250'
                     '.1.3.6.1.4.1.14760.2.1.2.2' --&amp;gt; '20151027095414'
                     '.1.3.6.1.4.1.14760.2.1.2.11' --&amp;gt; 'WFS_SYSE_DEVICE_STATUS: PhysicalName=CIM_CCDMWorkstationName=A362-2250 State=WFS_STAT_DEVONLINE (CIM_CCDM)'
                     '.1.3.6.1.4.1.14760.2.1.2.12' --&amp;gt; 'Device Cashin CCDM Module online'
                     '.1.3.6.1.4.1.14760.2.1.2.15' --&amp;gt; 'Cash/Cheque In'
=================== ICS_Notification attributes ==================
ClassName:           'Proview'
InstanceName:        'A362-2250'
EventName:           'ATM - A362-2250 - Device Cashin CCDM Module online'
Severity:            '5'
EventText:           'Proview/ATM Event: A362-2250 20151027095414 WFS_SYSE_DEVICE_STATUS: PhysicalName=CIM_CCDMWorkstationName=A362-2250 State=WFS_STAT_DEVONLINE (CIM_CCDM) Device Cashin CCDM Module online'
Category:            'SNMPTrap'
**Discard:             'YES'**
ForceOcc:            'A362-2250'
SuppressAgentOcc:    ''
UpdateUD:            ''
Expiration:          '600'
State:               'NOTIFY'
InMaintenance:       'FALSE'
ClearOnAcknowledge:  'TRUE'
TrapSource:          'Trap Processor'
EventType:           'MOMENTARY'
ASL:                 'proview.asl'
ElementClassName:    'Host'
ElementInstanceName: '10.10.54.82'
SysNameOrAddr:       'A362-2250'
UnknownAgent:        'CREATE'
LogFile:             'TRAPS-Proview.log'
UserDefined1:        '10.10.54.82'
UserDefined2:        ''
UserDefined3:        ''
UserDefined4:        ''
UserDefined5:        ''
UserDefined6:        ''
UserDefined7:        'Device Cashin CCDM Module online'
UserDefined8:        'Proview ATM Trap 1 from 10.10.54.82/10.10.54.82
MIB Module:     
wnProviewDeviceId:  A362-2250
wnProviewOriginalTime:  20151027095414
wnProviewServerTimed:   WFS_SYSE_DEVICE_STATUS: PhysicalName=CIM_CCDMWorkstationName=A362-2250 State=WFS_STAT_DEVONLINE (CIM_CCDM)
wnProviewEventType: Device Cashin CCDM Module online
wnProviewEventNumber:   Cash/Cheque In
wnProviewOriginalEventNumber:   
wnProviewDeviceState:   
wnProviewSetStateChange:    
wnProviewUnsetStateChange:  
wnProviewEventMask: 
wnProviewOriginalEventText: 
wnProviewEventText: 
wnProviewSetBitMask:    
wnProviewUnsetBitMask:  
wnProviewComponentName: 
wnProviewComponentState:    
wnProviewTransportAddress:  '
UserDefined9:        ''
UserDefined10:       ''
UserDefined11:        ''
UserDefined12:        ''
UserDefined13:        ''
UserDefined14:        ''
UserDefined15:        ''
UserDefined16:        ''
UserDefined17:        ''
UserDefined18:        ''
UserDefined19:        ''
UserDefined20:       ''
==================================================================
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;It is just not working at this time.  I am still seeing the Discarded records indexed in Splunk.&lt;/P&gt;

&lt;P&gt;Any assistance you can provide will be appreciated. &lt;/P&gt;

&lt;P&gt;bfnpmsz&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2015 15:57:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206847#M40820</guid>
      <dc:creator>bfnpmsz</dc:creator>
      <dc:date>2015-10-27T15:57:34Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my props.conf and transforms.conf to filter select events from one source file from getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206848#M40821</link>
      <description>&lt;P&gt;Try something like this for your props.conf entry&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[source::...\\d\\InCharge\\SAM\\smarts\\local\\logs\\TRAPS-Proview.log]
 TRANSFORMS-null= discards
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Tue, 27 Oct 2015 16:51:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206848#M40821</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-10-27T16:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my props.conf and transforms.conf to filter select events from one source file from getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206849#M40822</link>
      <description>&lt;P&gt;I removed the quotes as you suggested, seemed logical, no luck though.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[source::\\\\Alvionix03\\d\\InCharge\\SAM\\smarts\\local\\logs\\TRAPS-Proview.log]
TRANSFORMS-null= discards
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Still the events are getting indexed.  &lt;/P&gt;

&lt;P&gt;Any other ideas?&lt;/P&gt;

&lt;P&gt;bfnpmsz&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2015 17:37:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206849#M40822</guid>
      <dc:creator>bfnpmsz</dc:creator>
      <dc:date>2015-10-27T17:37:44Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my props.conf and transforms.conf to filter select events from one source file from getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206850#M40823</link>
      <description>&lt;P&gt;Can you try with exact stanza as mine (you seem to shared directory and I would suggest to try option without that)?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2015 20:25:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206850#M40823</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-10-27T20:25:22Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my props.conf and transforms.conf to filter select events from one source file from getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206851#M40824</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;[source::...\\d\\InCharge\\SAM\\smarts\\local\\logs\\TRAPS-Proview.log]
TRANSFORMS-null= discards
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Still no love....  All records are getting indexed.  The discards are still there.&lt;/P&gt;

&lt;P&gt;bfnpmsz&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2015 20:44:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206851#M40824</guid>
      <dc:creator>bfnpmsz</dc:creator>
      <dc:date>2015-10-27T20:44:36Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my props.conf and transforms.conf to filter select events from one source file from getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206852#M40825</link>
      <description>&lt;P&gt;Just to confirm, you're restarting Splunk after the change?&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2015 20:52:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206852#M40825</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2015-10-27T20:52:08Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my props.conf and transforms.conf to filter select events from one source file from getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206853#M40826</link>
      <description>&lt;P&gt;You need to deploy these files all of your Indexers (or if using them, Heavy Forwarders) and then restart all splunk instances there.  When verifying function, only check NEW events, events indexed previous to the restart will not be effected.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2015 03:46:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206853#M40826</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-10-28T03:46:41Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my props.conf and transforms.conf to filter select events from one source file from getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206854#M40827</link>
      <description>&lt;P&gt;Woodcock,&lt;/P&gt;

&lt;P&gt;Yeah,  I wish I have not tried that already.  I only have the one server with Splunk installed and so therefore one indexer.  Each time I have restarted Splunk and the Discarded records are still indexed.  The old records are not affected because they have been indexed before this change.  &lt;/P&gt;

&lt;P&gt;I am not sure where I am going wrong, but something is amiss.&lt;/P&gt;

&lt;P&gt;Thanks for your comment and help.&lt;BR /&gt;
bfnpmsz&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2015 20:58:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206854#M40827</guid>
      <dc:creator>bfnpmsz</dc:creator>
      <dc:date>2015-10-28T20:58:52Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my props.conf and transforms.conf to filter select events from one source file from getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206855#M40828</link>
      <description>&lt;P&gt;The OS is windows, right?&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 17:07:52 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206855#M40828</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-10-29T17:07:52Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my props.conf and transforms.conf to filter select events from one source file from getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206856#M40829</link>
      <description>&lt;P&gt;Yes, its Windows Server 2012.&lt;/P&gt;

&lt;P&gt;bfnpmsz&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 17:30:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206856#M40829</guid>
      <dc:creator>bfnpmsz</dc:creator>
      <dc:date>2015-10-29T17:30:09Z</dc:date>
    </item>
    <item>
      <title>Re: How do I edit my props.conf and transforms.conf to filter select events from one source file from getting indexed?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206857#M40830</link>
      <description>&lt;P&gt;Yes, a restart after each config change.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2015 21:37:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-do-I-edit-my-props-conf-and-transforms-conf-to-filter-select/m-p/206857#M40830</guid>
      <dc:creator>bfnpmsz</dc:creator>
      <dc:date>2015-10-29T21:37:49Z</dc:date>
    </item>
  </channel>
</rss>

