<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to remove information from forwarded data? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-information-from-forwarded-data/m-p/282808#M54057</link>
    <description>&lt;P&gt;cool, the more info you provide , the better we will be able to assist &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 19 Oct 2015 15:30:44 GMT</pubDate>
    <dc:creator>asimagu</dc:creator>
    <dc:date>2015-10-19T15:30:44Z</dc:date>
    <item>
      <title>How to remove information from forwarded data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-information-from-forwarded-data/m-p/282804#M54053</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;

&lt;P&gt;This is my topology:&lt;/P&gt;

&lt;P&gt;Splunk Forwarder (with local copy of data) -----&amp;gt; Main Splunk&lt;/P&gt;

&lt;P&gt;The forwarder is adding sourcetype from regex etc... and it appears in the main Splunk, but I prefer to have raw data. How is it possible to have this without deleting rules on the Splunk forwarder?&lt;/P&gt;

&lt;P&gt;Thanks,&lt;/P&gt;

&lt;P&gt;Damien&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 09:20:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-information-from-forwarded-data/m-p/282804#M54053</guid>
      <dc:creator>ddarmand</dc:creator>
      <dc:date>2015-10-19T09:20:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove information from forwarded data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-information-from-forwarded-data/m-p/282805#M54054</link>
      <description>&lt;P&gt;so you are using a HW Forwarder?? why don't you try using a UF?&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 09:45:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-information-from-forwarded-data/m-p/282805#M54054</guid>
      <dc:creator>asimagu</dc:creator>
      <dc:date>2015-10-19T09:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove information from forwarded data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-information-from-forwarded-data/m-p/282806#M54055</link>
      <description>&lt;P&gt;because i need to keep local copy of events on the forwarder !&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 10:24:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-information-from-forwarded-data/m-p/282806#M54055</guid>
      <dc:creator>ddarmand</dc:creator>
      <dc:date>2015-10-19T10:24:35Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove information from forwarded data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-information-from-forwarded-data/m-p/282807#M54056</link>
      <description>&lt;P&gt;What makes you think that your sourcetype is being added to your raw event?  I am unaware of any automatic (i.e. accidental) way that this could happen and to deliberately make it happen, although not difficult, is certainly something that takes some work.  I suspect that your raw events are actually OK but you can see for yourself like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;... | table sourcetype _raw
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;You will probably see that the field &lt;CODE&gt;_raw&lt;/CODE&gt; always has an identical/unmodified copy of your raw events.&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 13:32:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-information-from-forwarded-data/m-p/282807#M54056</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-10-19T13:32:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove information from forwarded data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-information-from-forwarded-data/m-p/282808#M54057</link>
      <description>&lt;P&gt;cool, the more info you provide , the better we will be able to assist &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 19 Oct 2015 15:30:44 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-information-from-forwarded-data/m-p/282808#M54057</guid>
      <dc:creator>asimagu</dc:creator>
      <dc:date>2015-10-19T15:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove information from forwarded data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-information-from-forwarded-data/m-p/282809#M54058</link>
      <description>&lt;P&gt;It's added because i have some configurations to do this in props.conf transforms.conf ect... but i dont wan't to have these infos on the forwarded data&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 07:54:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-information-from-forwarded-data/m-p/282809#M54058</guid>
      <dc:creator>ddarmand</dc:creator>
      <dc:date>2015-10-20T07:54:10Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove information from forwarded data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-information-from-forwarded-data/m-p/282810#M54059</link>
      <description>&lt;P&gt;OK, I am TOTALLY confused.  You are &lt;EM&gt;deliberately&lt;/EM&gt; adding stuff to your raw events but you would like to not do so?  Back all the way up and &lt;EM&gt;FULLY&lt;/EM&gt; explain your existing configurations (and maybe why they are that way) and the explain your &lt;EM&gt;desired&lt;/EM&gt; end state.  As it is, right now, I am utterly confounded.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2015 15:07:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-information-from-forwarded-data/m-p/282810#M54059</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-10-20T15:07:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove information from forwarded data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-information-from-forwarded-data/m-p/282811#M54060</link>
      <description>&lt;P&gt;Ok, sorry i will try to explain this :&lt;/P&gt;

&lt;P&gt;&lt;A href="http://zupimages.net/viewer.php?id=15/43/mnyy.png"&gt;http://zupimages.net/viewer.php?id=15/43/mnyy.png&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;&lt;IMG src="http://zupimages.net/viewer.php?id=15/43/mnyy.png" alt="http://zupimages.net/viewer.php?id=15/43/mnyy.png" /&gt;&lt;/P&gt;

&lt;P&gt;As you can see, we have two types of users A and B.&lt;/P&gt;

&lt;P&gt;I want to see on the main splunk for user B the logs without modifications by the heavy forwarder (as they come by syslog)&lt;/P&gt;

&lt;P&gt;These modifications is adding sourcetype for example with props.conf and transforms.conf ect...&lt;/P&gt;

&lt;P&gt;But user A need these modifications.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2015 09:16:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-information-from-forwarded-data/m-p/282811#M54060</guid>
      <dc:creator>ddarmand</dc:creator>
      <dc:date>2015-10-21T09:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to remove information from forwarded data?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-information-from-forwarded-data/m-p/282812#M54061</link>
      <description>&lt;P&gt;If I understand you correctly, this is your situation:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;We have two types of users: A and B both generating the same events that are coming through syslog.  For type-B users, we'd like the logs without modifications (added fields, e.g. sourcetype) by the heavy forwarder (just as they come by syslog).  For type-A users, we'd like to add/keep these modifications.
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;If this is correct, then you need to build a REGEX that can match type-A users but not type-B users.  Once this is done, you need to modify the stanza in &lt;CODE&gt;transforms.conf&lt;/CODE&gt; that is adding the fields so that it has a &lt;CODE&gt;REGEX=&lt;/CODE&gt; line.   That should do it.&lt;/P&gt;</description>
      <pubDate>Wed, 21 Oct 2015 16:42:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-remove-information-from-forwarded-data/m-p/282812#M54061</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2015-10-21T16:42:55Z</dc:date>
    </item>
  </channel>
</rss>

