<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is there a way to only forward certain log events? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-only-forward-certain-log-events/m-p/247660#M47766</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Is there a way of only sending certain events from a log file via a forwarder?&lt;/P&gt;

&lt;P&gt;E.g. our log files contain a lot of noise that I don't want to send to Splunk (mainly for network performance reasons), the logs are in the structure of:&lt;/P&gt;

&lt;P&gt;(blank line)&lt;BR /&gt;
[Header line 1 with &lt;STRONG&gt;log_type&lt;/STRONG&gt;]&lt;BR /&gt;
[Header line 2]&lt;BR /&gt;
free text body of contents of log message&lt;BR /&gt;
(blank line)&lt;/P&gt;

&lt;P&gt;How can I configure the forwarder to only send log blocks of certain "&lt;STRONG&gt;log_type&lt;/STRONG&gt;"s?&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Fri, 20 Jan 2017 11:11:24 GMT</pubDate>
    <dc:creator>mattbrowne</dc:creator>
    <dc:date>2017-01-20T11:11:24Z</dc:date>
    <item>
      <title>Is there a way to only forward certain log events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-only-forward-certain-log-events/m-p/247660#M47766</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Is there a way of only sending certain events from a log file via a forwarder?&lt;/P&gt;

&lt;P&gt;E.g. our log files contain a lot of noise that I don't want to send to Splunk (mainly for network performance reasons), the logs are in the structure of:&lt;/P&gt;

&lt;P&gt;(blank line)&lt;BR /&gt;
[Header line 1 with &lt;STRONG&gt;log_type&lt;/STRONG&gt;]&lt;BR /&gt;
[Header line 2]&lt;BR /&gt;
free text body of contents of log message&lt;BR /&gt;
(blank line)&lt;/P&gt;

&lt;P&gt;How can I configure the forwarder to only send log blocks of certain "&lt;STRONG&gt;log_type&lt;/STRONG&gt;"s?&lt;/P&gt;

&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2017 11:11:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-only-forward-certain-log-events/m-p/247660#M47766</guid>
      <dc:creator>mattbrowne</dc:creator>
      <dc:date>2017-01-20T11:11:24Z</dc:date>
    </item>
    <item>
      <title>Re: Is there a way to only forward certain log events?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-only-forward-certain-log-events/m-p/247661#M47767</link>
      <description>&lt;P&gt;You have two approaches here. &lt;/P&gt;

&lt;P&gt;1) You could use a universal forwarder to specify only the files you want to forward &lt;BR /&gt;
2) You should use a heavy forwarder to pre-parse the data and send any junk data to nullqueue&lt;/P&gt;

&lt;P&gt;If the "noise" is mixed in with the logs you want to send, you should go with option 2. If the "noise" is comprised of logs you don't want, you should go with option 1. If you need more of an explanation, then provide more details about where the noise is&lt;/P&gt;

&lt;P&gt;&lt;A href="https://answers.splunk.com/answers/11617/route-unwanted-logs-to-a-null-queue.html"&gt;https://answers.splunk.com/answers/11617/route-unwanted-logs-to-a-null-queue.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Jan 2017 13:03:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Is-there-a-way-to-only-forward-certain-log-events/m-p/247661#M47767</guid>
      <dc:creator>skoelpin</dc:creator>
      <dc:date>2017-01-20T13:03:11Z</dc:date>
    </item>
  </channel>
</rss>

