<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Help troubleshooting why events are not filtered to nullQueue with my props.conf and transforms.conf ? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Help-troubleshooting-why-events-are-not-filtered-to-nullQueue/m-p/234668#M45723</link>
    <description>&lt;P&gt;Thank you, this worked. So here is a question regarding License, Do the events getting dropped at the indexer count towards the capacity? Is it capacity getting to the indexer, or capacity of data indexed?&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jun 2016 13:59:59 GMT</pubDate>
    <dc:creator>tomcochran</dc:creator>
    <dc:date>2016-06-30T13:59:59Z</dc:date>
    <item>
      <title>Help troubleshooting why events are not filtered to nullQueue with my props.conf and transforms.conf ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-troubleshooting-why-events-are-not-filtered-to-nullQueue/m-p/234665#M45720</link>
      <description>&lt;P&gt;The input is working and the events are getting to Splunk. I am trying to get a filter going to drop noisy events. I have created an app that is deployed via a configuration server. I have tried this many different ways, but it doesn't seem to drop the events. The app is being pushed to the Universal Forwarder on Windows. The regex matches on online tools.&lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[SAP_portal_security_audit]
TRANSFORMS-set = discard_events
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; [discard_events]
 REGEX = (ACCESS\.ERROR|USERMAPPING\.USE)
 DEST_KEY = queue
 FORMAT = nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Log data&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;.0&amp;#8;#2016 06 29 08:54:55:906#0-500#Info#/System/Security/Audit/UserMapping#
#BC-JAS-SEC-UME#com.sap.security.core.sda#C0000A980ACE0ACF0000000600003AE4#28973850000000004#sap.com/irj#com.sap.security.core.util.SecurityAudit#Guest#0##90B5B81E3DA611E6B986000001BA1B1A#90b5b81e3da611e6b986000001ba1b1a#90b5b81e3da611e6b986000001ba1b1a#0#Thread[pool-2141-thread-1,5,Dedicated_Application_Thread]#Plain##
User mapping used   | USERMAPPING.USE   | USER.PRIVATE_DATASOURCE.un:eServices  |   | systemtype=[SAP_CRM], system=["SAP_CRM" (system landscape: "EnterprisePortal")], remote user ID=[ZESRVUSER], uses strong encryption=[true]#


#2.0&amp;#8;#2016 06 29 10:41:50:911#0-500#Warning#/System/Security/Audit/Access#
#EP-KM-FWK-RF#sap.com/com.sap.netweaver.bc.rf#C0000A989048C7010000000400000EA0#2778350000000004#sap.com/eServicesMasthead#com.sapportals.wcm.repository.security.SecurityAudit$AccessLog#UKSHEPA#16689##FCBF8AB33E0F11E6CA770000002A64EE#fb491e783e0f11e6c3fb0000002a64ee#fb491e783e0f11e6c3fb0000002a64ee#0#Thread[1047252450|pcd:portal_content/bungeContent/protectedContent/authenticatedDesktop/frameworkPages/authenticatedFrameworkPage/eServicesLightMasthead\#com%2esap%2eportal%2enavigation%2eportallauncher%2edefault.pcd%3aportal_content%2fbungeContent%2fprotectedContent%2fauthenticatedDesktop%2fframeworkPages%2fauthenticatedFrameworkPage.eServicesLightMasthead,5,Managed_Application_Thread]#Plain##
UKSHEPA | ACCESS.ERROR  | /documents/Public Documents/AgSite/SiteImages/b4b99ce4da58004ef7e8614edb99e3d2.xml    | leaf_write_content,leaf_write_properties#
    6/29/16 
11:03:07.943 AM 
#2.0&amp;#8;#2016 06 29 11:03:07:943#0-500#Warning#/System/Security/Audit/Access#
#EP-KM-FWK-RF#sap.com/com.sap.netweaver.bc.rf#C0000A9890453995000000CE00003A30#6820051000000004#sap.com/eServicesPublic#com.sapportals.wcm.repository.security.SecurityAudit$AccessLog#Guest#0##F59B7BD13E1211E6AE430000006810D3#f59b7bd13e1211e6ae430000006810d3#f59b7bd13e1211e6ae430000006810d3#0#Thread[1784794969|pcd:portal_content/bungeContent/publicContent/roles/eServices_Home/publicHome/locationInfoTabbedContainer/PersonnelSummary\#com%2esap%2eportal%2enavigation%2eportallauncher%2eanonymous.pcd%3aportal_content%2fbungeContent%2fpublicContent%2fanonymousLightDesktop%2fframeworkPages%2fanonymousLightFramework.com%2esap%2eportal%2elightinnerpage.com%2esap%2eportal%2elightcontentarea.content.locationInfoTabbedContainer.PersonnelSummary,5,Managed_Application_Thread]#Plain##
Guest   | ACCESS.ERROR  | /documents/Public Documents/AgSite/Personnel/9f40e230b555f773b47ffb300514e66e.xml | leaf_write_content,leaf_write_properties#
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 29 Jun 2016 16:26:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-troubleshooting-why-events-are-not-filtered-to-nullQueue/m-p/234665#M45720</guid>
      <dc:creator>tomcochran</dc:creator>
      <dc:date>2016-06-29T16:26:45Z</dc:date>
    </item>
    <item>
      <title>Re: Help troubleshooting why events are not filtered to nullQueue with my props.conf and transforms.conf ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-troubleshooting-why-events-are-not-filtered-to-nullQueue/m-p/234666#M45721</link>
      <description>&lt;P&gt;Hi tomcochran, &lt;/P&gt;

&lt;P&gt;i guess you have deployed the configuration above on your forwarder? If so, thats the problem (i assume your configuration is correct) ! &lt;/P&gt;

&lt;P&gt;The UniversalForwarder does not parse any of the events he is forwarding. Just bring the configuration to your indexer and it should work. &lt;/P&gt;

&lt;P&gt;I hope it helps.&lt;/P&gt;

&lt;P&gt;Greetings&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2016 05:26:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-troubleshooting-why-events-are-not-filtered-to-nullQueue/m-p/234666#M45721</guid>
      <dc:creator>hgrow</dc:creator>
      <dc:date>2016-06-30T05:26:16Z</dc:date>
    </item>
    <item>
      <title>Re: Help troubleshooting why events are not filtered to nullQueue with my props.conf and transforms.conf ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-troubleshooting-why-events-are-not-filtered-to-nullQueue/m-p/234667#M45722</link>
      <description>&lt;P&gt;I solved a similar issue configuring two stanzas in transforms.conf and inserting two commands in props.conf.&lt;BR /&gt;
note that it's important the order between the two commands in props.conf (the order of stanzas in transforms.conf isn't important):&lt;/P&gt;

&lt;UL&gt;
&lt;LI&gt;to take only a set of logs discarding the others:  before nullqueue and after the log stanza &lt;/LI&gt;
&lt;LI&gt;to take all the logs discarding only a set of logs before the log stanza and after null queue&lt;/LI&gt;
&lt;/UL&gt;

&lt;P&gt;in other words: before the command with all the logs (REGEX=.) and after the command with the set of logs you want (REGEX=xxxx).&lt;/P&gt;

&lt;P&gt;see the following example where set_AS are the logs I want to index, nullqueue are the logs I want to discard.&lt;/P&gt;

&lt;P&gt;in props.conf&lt;BR /&gt;
TRANSFORMS-set-AS=set_nullqueue,set_AS&lt;/P&gt;

&lt;P&gt;in transforms.conf&lt;/P&gt;

&lt;H1&gt;nullqueue&lt;/H1&gt;

&lt;P&gt;[set_nullqueue]&lt;BR /&gt;
REGEX=.&lt;BR /&gt;
DEST_KEY=queue&lt;BR /&gt;
FORMAT=nullQueue&lt;/P&gt;

&lt;H1&gt;AS&lt;/H1&gt;

&lt;P&gt;[set_AS]&lt;BR /&gt;
REGEX=SRVE&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = indexQueue&lt;/P&gt;

&lt;P&gt;Bye.&lt;/P&gt;

&lt;P&gt;Giuseppe&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 02:53:46 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-troubleshooting-why-events-are-not-filtered-to-nullQueue/m-p/234667#M45722</guid>
      <dc:creator>gcusello</dc:creator>
      <dc:date>2020-09-30T02:53:46Z</dc:date>
    </item>
    <item>
      <title>Re: Help troubleshooting why events are not filtered to nullQueue with my props.conf and transforms.conf ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-troubleshooting-why-events-are-not-filtered-to-nullQueue/m-p/234668#M45723</link>
      <description>&lt;P&gt;Thank you, this worked. So here is a question regarding License, Do the events getting dropped at the indexer count towards the capacity? Is it capacity getting to the indexer, or capacity of data indexed?&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2016 13:59:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-troubleshooting-why-events-are-not-filtered-to-nullQueue/m-p/234668#M45723</guid>
      <dc:creator>tomcochran</dc:creator>
      <dc:date>2016-06-30T13:59:59Z</dc:date>
    </item>
    <item>
      <title>Re: Help troubleshooting why events are not filtered to nullQueue with my props.conf and transforms.conf ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-troubleshooting-why-events-are-not-filtered-to-nullQueue/m-p/234669#M45724</link>
      <description>&lt;P&gt;Hi tomcochran, &lt;/P&gt;

&lt;P&gt;i'm glad i could help. I made my comment an answer. Can you do me a favor and accept it?&lt;/P&gt;

&lt;P&gt;To answer your license questions, it's capacity of data indexed. The events send to nullqueue wont stress your licence. &lt;/P&gt;

&lt;P&gt;Greetings&lt;BR /&gt;
hgrow&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2016 14:09:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-troubleshooting-why-events-are-not-filtered-to-nullQueue/m-p/234669#M45724</guid>
      <dc:creator>hgrow</dc:creator>
      <dc:date>2016-06-30T14:09:01Z</dc:date>
    </item>
    <item>
      <title>Re: Help troubleshooting why events are not filtered to nullQueue with my props.conf and transforms.conf ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-troubleshooting-why-events-are-not-filtered-to-nullQueue/m-p/234670#M45725</link>
      <description>&lt;P&gt;Awesome, thank you so much.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2016 18:32:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-troubleshooting-why-events-are-not-filtered-to-nullQueue/m-p/234670#M45725</guid>
      <dc:creator>tomcochran</dc:creator>
      <dc:date>2016-06-30T18:32:09Z</dc:date>
    </item>
    <item>
      <title>Re: Help troubleshooting why events are not filtered to nullQueue with my props.conf and transforms.conf ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Help-troubleshooting-why-events-are-not-filtered-to-nullQueue/m-p/234671#M45726</link>
      <description>&lt;P&gt;I have tried &lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;props.conf&lt;/STRONG&gt;&lt;BR /&gt;
[hfss_source]&lt;BR /&gt;
TRANSFORMS-set= set_parsing,set_null&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;transforms.conf&lt;/STRONG&gt;&lt;BR /&gt;
[set_null]&lt;BR /&gt;
REGEX = standby&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = nullQueue&lt;/P&gt;

&lt;P&gt;[set_parsing]&lt;BR /&gt;
REGEX =.&lt;BR /&gt;
DEST_KEY=queue&lt;BR /&gt;
FORMAT=indexQueue&lt;/P&gt;

&lt;P&gt;Trying to get rid of all entries with the word "standby" in it, but everything gets indexed.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;splunk cmd btool props list hfss_source&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;
shows correctly, but&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;&lt;EM&gt;splunk cmd btool transforms list hfss_source&lt;/EM&gt;&lt;/STRONG&gt;&lt;BR /&gt;
shows absolutely nothing&lt;/P&gt;

&lt;P&gt;Any ideas ? I am completely lost, I feel I have done what everybody is writing will work, but I just can't get it to work?&lt;/P&gt;

&lt;P&gt;Any help would be greatly appriciated&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 23:58:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Help-troubleshooting-why-events-are-not-filtered-to-nullQueue/m-p/234671#M45726</guid>
      <dc:creator>henrikstorm</dc:creator>
      <dc:date>2020-09-29T23:58:29Z</dc:date>
    </item>
  </channel>
</rss>

