<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: filter events based on regex and index remaining - props and transforms in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/filter-events-based-on-regex-and-index-remaining-props-and/m-p/328987#M61047</link>
    <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206320"&gt;@493669&lt;/a&gt; ,&lt;/P&gt;

&lt;P&gt;It still doesnt work. It nulls entire log.&lt;/P&gt;

&lt;P&gt;Here is the complete sample log&lt;/P&gt;

&lt;P&gt;20180305 06:10:43,769 EST DEBUG sql.Connection [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {conn-11499536} Connection&lt;BR /&gt;
20180305 06:10:43,769 EST DEBUG sql.Connection [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {conn-11499536} Preparing Call: { call SA_TAO_AIP_CASH_MGT_TXN_PKG.get_cash_txn_dtl_by_cp_id(?,?) }&lt;BR /&gt;
20180305 06:10:43,769 EST DEBUG sql.PreparedStatement [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {pstm-11499537} Executing Statement: { call SA_TAO_AIP_CASH_MGT_TXN_PKG.get_cash_txn_dtl_by_cp_id(?,?) }&lt;BR /&gt;
20180305 06:10:43,769 EST DEBUG sql.PreparedStatement [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {pstm-11499537} Parameters: [55858397233]&lt;BR /&gt;
20180305 06:10:43,769 EST DEBUG sql.PreparedStatement [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {pstm-11499537} Types: [java.lang.Long]&lt;BR /&gt;
20180305 06:10:43,774 EST DEBUG sql.Connection [WorkflowManager_10027887_55656942908_55666096052_3006]  - {conn-11499538} Connection&lt;BR /&gt;
20180305 06:10:43,774 EST DEBUG sql.Connection [WorkflowManager_10027887_55656942908_55666096052_3006]  - {conn-11499538} Preparing Call: { call SA_TAO_AIP_COMMON_PKG.GET_PORTF_INSTANCE_LOTS(?, ?) }&lt;BR /&gt;
20180305 06:10:43,774 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55656942908_55666096052_3006]  - {pstm-11499539} Executing Statement: { call SA_TAO_AIP_COMMON_PKG.GET_PORTF_INSTANCE_LOTS(?, ?) }&lt;BR /&gt;
20180305 06:10:43,774 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55656942908_55666096052_3006]  - {pstm-11499539} Parameters: [398207947]&lt;BR /&gt;
20180305 06:10:43,774 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55656942908_55666096052_3006]  - {pstm-11499539} Types: [java.lang.Long]&lt;BR /&gt;
20180305 06:10:43,791 EST INFO  domain.CashDomain [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - Available Cash for [investablePortfolioId=55868440408, sleeve=ROP, lot=INITIAL, withLiq=false] is: 1219.5500000 &lt;BR /&gt;
20180305 06:10:43,791 EST DEBUG sql.Connection [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {conn-11499540} Connection&lt;BR /&gt;
20180305 06:10:43,791 EST DEBUG sql.Connection [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {conn-11499540} Preparing Call: { ? = call sa_tao_aip_parameter_pkg.get_ip_portf_param_value(?, ?) }&lt;BR /&gt;
20180305 06:10:43,791 EST DEBUG sql.PreparedStatement [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {pstm-11499541} Executing Statement: { ? = call sa_tao_aip_parameter_pkg.get_ip_portf_param_value(?, ?) }&lt;BR /&gt;
20180305 06:10:43,791 EST DEBUG sql.PreparedStatement [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {pstm-11499541} Parameters: [CASH_TXN_THRESHOLD_DAYS, 55868440408]&lt;BR /&gt;
20180305 06:10:43,791 EST DEBUG sql.PreparedStatement [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {pstm-11499541} Types: [java.lang.String, java.lang.Long]&lt;BR /&gt;
20180305 06:10:43,801 EST INFO  domain.CashDomain [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - Cash transaction threshold days value for [investablePortfolioId=55868440408] is: 60&lt;BR /&gt;
20180305 06:10:43,802 EST DEBUG sql.Connection [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {conn-11499542} Connection&lt;BR /&gt;
20180305 06:10:43,802 EST DEBUG sql.Connection [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {conn-11499542} Preparing Call: { call sa_tao_aip_portf_metric_pkg.ins_portf_metric_val(?) }&lt;BR /&gt;
20180305 06:10:43,802 EST DEBUG sql.PreparedStatement [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {pstm-11499543} Executing Statement: { call sa_tao_aip_portf_metric_pkg.ins_portf_metric_val(?) }&lt;BR /&gt;
20180305 06:10:43,802 EST DEBUG sql.PreparedStatement [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {pstm-11499543} Parameters: [oracle.sql.ARRAY@10b46d2d]&lt;BR /&gt;
20180305 06:10:43,802 EST DEBUG sql.PreparedStatement [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {pstm-11499543} Types: [oracle.sql.ARRAY]&lt;BR /&gt;
20180305 06:10:43,829 EST INFO  workflow.TransactionalWorkflowOperation [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - Returning to Workflow manager, returnCode[0]&lt;BR /&gt;
20180305 06:10:43,829 EST INFO  workflow.TransactionalWorkflowOperation [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  -  ---------- Committing all transactions using (workflowTransaction) transaction manager ---------- &lt;BR /&gt;
20180305 06:10:43,848 EST DEBUG sql.Connection [WorkflowManager_10027887_55858397233_55868440408_2000]  - {conn-11499544} Connection&lt;BR /&gt;
20180305 06:10:43,848 EST DEBUG sql.Connection [WorkflowManager_10027887_55858397233_55868440408_2000]  - {conn-11499544} Preparing Call: { call SA_TAO_AIP_PORTFOLIO_PKG.GET_ALL_INV_PORTF_FOR_CLIENT(?, ?) }&lt;BR /&gt;
20180305 06:10:43,848 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499545} Executing Statement: { call SA_TAO_AIP_PORTFOLIO_PKG.GET_ALL_INV_PORTF_FOR_CLIENT(?, ?) }&lt;BR /&gt;
20180305 06:10:43,848 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499545} Parameters: [55858397233]&lt;BR /&gt;
20180305 06:10:43,848 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499545} Types: [java.lang.Long]&lt;BR /&gt;
20180305 06:10:43,856 EST DEBUG sql.Connection [WorkflowManager_10027887_55858397233_55868440408_2000]  - {conn-11499546} Connection&lt;BR /&gt;
20180305 06:10:43,856 EST DEBUG sql.Connection [WorkflowManager_10027887_55858397233_55868440408_2000]  - {conn-11499546} Preparing Call: { call SA_TAO_AIP_OPT_TEMPLATE_PKG.get_portf_strtgy_ovrrde(?,?) }&lt;BR /&gt;
20180305 06:10:43,856 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499547} Executing Statement: { call SA_TAO_AIP_OPT_TEMPLATE_PKG.get_portf_strtgy_ovrrde(?,?) }&lt;BR /&gt;
20180305 06:10:43,856 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499547} Parameters: [55868440408]&lt;BR /&gt;
20180305 06:10:43,856 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499547} Types: [java.lang.Long]&lt;BR /&gt;
20180305 06:10:43,867 EST DEBUG sql.Connection [WorkflowManager_10027887_55858397233_55868440408_2000]  - {conn-11499548} Connection&lt;BR /&gt;
20180305 06:10:43,867 EST DEBUG sql.Connection [WorkflowManager_10027887_55858397233_55868440408_2000]  - {conn-11499548} Preparing Call: { call sa_tao_aip_portf_metric_pkg.get_portf_metric_val(?, ?, ?) }&lt;BR /&gt;
20180305 06:10:43,867 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499549} Executing Statement: { call sa_tao_aip_portf_metric_pkg.get_portf_metric_val(?, ?, ?) }&lt;BR /&gt;
20180305 06:10:43,867 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499549} Parameters: [10027887, 55868440408]&lt;BR /&gt;
20180305 06:10:43,867 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499549} Types: [java.lang.Long, java.lang.Long]&lt;/P&gt;</description>
    <pubDate>Tue, 29 Sep 2020 18:19:07 GMT</pubDate>
    <dc:creator>sarnagar</dc:creator>
    <dc:date>2020-09-29T18:19:07Z</dc:date>
    <item>
      <title>filter events based on regex and index remaining - props and transforms</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/filter-events-based-on-regex-and-index-remaining-props-and/m-p/328982#M61042</link>
      <description>&lt;P&gt;Im trying to filter out events based on regex and index the remaining events based on below configs..But it doesn't seem to work...Can someone pls help..&lt;/P&gt;

&lt;P&gt;In props.conf&lt;/P&gt;

&lt;P&gt;[sourcetypename]&lt;BR /&gt;
TRANSFORMS-set= setnull,setparsing&lt;/P&gt;

&lt;P&gt;In transforms.conf&lt;/P&gt;

&lt;P&gt;[setnull]&lt;BR /&gt;
REGEX = (setting all transactions (.&lt;EM&gt;) transaction cases)|(Types:\s[.&lt;/EM&gt;])|(FindingCall)|(Clearing junk and context) &lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = nullQueue&lt;BR /&gt;
[setparsing]&lt;BR /&gt;
REGEX = .&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = indexQueue &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:17:48 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/filter-events-based-on-regex-and-index-remaining-props-and/m-p/328982#M61042</guid>
      <dc:creator>sarnagar</dc:creator>
      <dc:date>2020-09-29T18:17:48Z</dc:date>
    </item>
    <item>
      <title>Re: filter events based on regex and index remaining - props and transforms</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/filter-events-based-on-regex-and-index-remaining-props-and/m-p/328983#M61043</link>
      <description>&lt;P&gt;here use &lt;CODE&gt;[setnull]&lt;/CODE&gt; only no need of &lt;CODE&gt;[setparsing]&lt;/CODE&gt;...remove it and then restart...and if still not working then share your sample events which you need to filter out.&lt;/P&gt;</description>
      <pubDate>Sun, 04 Mar 2018 08:57:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/filter-events-based-on-regex-and-index-remaining-props-and/m-p/328983#M61043</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-03-04T08:57:23Z</dc:date>
    </item>
    <item>
      <title>Re: filter events based on regex and index remaining - props and transforms</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/filter-events-based-on-regex-and-index-remaining-props-and/m-p/328984#M61044</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206320"&gt;@493669&lt;/a&gt; ,&lt;/P&gt;

&lt;P&gt;I tried removing the setparsing part and it removes all the events and nothing is indexed.&lt;BR /&gt;
I need only lines that contain those phrases to be removed.&lt;/P&gt;

&lt;P&gt;Need to ignore lines containing below words:&lt;BR /&gt;
"Preparing Call"&lt;BR /&gt;
"Clearing Module Context"&lt;BR /&gt;
"Types: [&lt;EM&gt;]"&lt;BR /&gt;
"Committing all transactions using (&lt;/EM&gt;) transaction manager" &lt;/P&gt;

&lt;P&gt;Regex used:&lt;BR /&gt;&lt;BR /&gt;
(Committing all transactions using (.&lt;EM&gt;) transaction manager)|(Types:\s[.&lt;/EM&gt;])|(Preparing Call)|(Clearing Module Context) &lt;/P&gt;

&lt;P&gt;Ex of Logfile:&lt;/P&gt;

&lt;P&gt;20180302 05:02:28,856 EST DEBUG sql.PreparedStatement [WorkflowManager_10027886_55808724927]  - {pstm-47402055} Types: [java.lang.Long, java.lang.String, java.lang.String, java.lang.Long, null, null, java.lang.String, java.lang.String, null, java.sql.Timestamp, null, null, java.lang.Long, null, null, null]&lt;BR /&gt;
20180302 05:02:28,856 EST DEBUG sql.PreparedStatement [WorkflowManager_10027886_58055999998_58072708329_7001]  - {pstm-47402058} Types: [java.lang.Long]&lt;BR /&gt;
20180302 05:02:28,856 EST DEBUG sql.PreparedStatement [WorkflowManager_10027886_61129156140]  - {pstm-47402059} Types: [java.lang.Long]&lt;BR /&gt;
20180302 05:02:28,858 EST DEBUG sql.PreparedStatement [WorkflowManager_10027886_61129156140]  - {pstm-47402061} Types: [java.lang.Long, java.lang.String, java.lang.String, java.lang.Long, null, null, java.lang.String, java.lang.String, null, java.sql.Timestamp, null, null, java.lang.Long, null, null, null]&lt;BR /&gt;
20180302 05:02:28,859 EST DEBUG sql.PreparedStatement [WorkflowManager_10027886_58055999998_58072708329_7001]  - {pstm-47402064} Types: [java.lang.Long]&lt;BR /&gt;
20180302 05:02:28,859 EST DEBUG sql.PreparedStatement [WorkflowManager_10027886_55808724927]  - {pstm-47402065} Types: [java.lang.Long, java.lang.Long, java.lang.Long]&lt;BR /&gt;
20180302 05:02:28,866 EST DEBUG sql.PreparedStatement [WorkflowManager_10027886_61129156140]  - {pstm-47402068} Types: [java.lang.Long, java.lang.Long, java.lang.Long]&lt;BR /&gt;
20180302 05:02:28,866 EST DEBUG sql.PreparedStatement [ConstraintManagerService_10027886_59615007125_59266246402_3003]  - {pstm-47402075} Types: [java.lang.Long, null, null]&lt;BR /&gt;
20180302 05:02:28,866 EST DEBUG sql.PreparedStatement [ConstraintManagerService_10027886_35770283302_35772759397_3003]  - {pstm-47402079} Types: [java.lang.Long, null, null]&lt;BR /&gt;
20180302 05:02:28,866 EST DEBUG sql.PreparedStatement [WorkflowManager_10027886_58055999998_58072708329_7001]  - {pstm-47402081} Types: [java.lang.Long]&lt;BR /&gt;
20180302 05:02:28,866 EST DEBUG sql.PreparedStatement [ConstraintManagerService_10027886_45166366355_45172697064_3003]  - {pstm-47402074} Types: [java.lang.Long, null, null]&lt;BR /&gt;
For NOT "Committing all transactions using (*) transaction manager" &lt;BR /&gt;
20180302 05:04:27,239 EST INFO  workflow.TransactionalWorkflowOperation [InvestablePortfolioConstraints_10027886_56399425167_56411171958]  -  ---------- Committing all transactions using (workflowTransaction) transaction manager ----------&lt;BR /&gt;
20180302 05:04:27,253 EST INFO  workflow.TransactionalWorkflowOperation [OptimizerService_10027886_63883247085_62514894824_4010]  -  ---------- Committing all transactions using (workflowTransaction) transaction manager ----------&lt;BR /&gt;
20180302 05:04:27,255 EST INFO  workflow.TransactionalWorkflowOperation [ClientPortfolioDatamartLoadService_10027886_55546646750_55555552651_1999]  -  ---------- Committing all transactions using (workflowTransaction) transaction manager ----------&lt;BR /&gt;
20180302 05:04:27,266 EST INFO  workflow.TransactionalWorkflowOperation&lt;BR /&gt;
Clearing Module Context asdfhasduoifhuiase\djlkfgasdui  [PostOptPortfolioScores_10027886_42388259809_42393917628_8008]  -  ---------- Committing all transactions using (workflowTransaction) transaction manager ----------&lt;BR /&gt;
20180302 05:04:27,274 EST INFO  workflow.TransactionalWorkflowOperation [PostOptPortfolioScores_10027886_62087947442_62515891686_8008]  -  ---------- Committing all transactions using (workflowTransaction) transaction manager ----------&lt;BR /&gt;
20180302 05:04:27,278 EST INFO  workflow.TransactionalWorkflowOperation [WorkflowManager_10027886_52909311282_52946733021_4000]  -  ---------- Committing all transactions using (workflowTransaction) transaction manager ----------&lt;BR /&gt;
20180302 05:04:27,282 EST INFO  workflow.TransactionalWorkflowOperation [ClientPortfolioInitializationService_10027886_35383068482_35385507500_2700]  -  ---------- Committing all transactions using (workflowTransaction) transaction manager ----------&lt;BR /&gt;
20180305 06:10:43,829 EST INFO  workflow.TransactionalWorkflowOperation [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  -  ---------- Committing all transactions using (workflowTransaction) transaction manager ---------- &lt;BR /&gt;
20180305 06:10:43,848 EST DEBUG sql.Connection [WorkflowManager_10027887_55858397233_55868440408_2000]  - {conn-11499544} Connection&lt;BR /&gt;
20180305 06:10:43,848 EST DEBUG sql.Connection [WorkflowManager_10027887_55858397233_55868440408_2000]  - {conn-11499544} Preparing Call: { call SA_TAO_AIP_PORTFOLIO_PKG.GET_ALL_INV_PORTF_FOR_CLIENT(?, ?) }&lt;BR /&gt;
20180305 06:10:43,848 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499545} Executing Statement: { call SA_TAO_AIP_PORTFOLIO_PKG.GET_ALL_INV_PORTF_FOR_CLIENT(?, ?) }&lt;BR /&gt;
20180305 06:10:43,848 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499545} Parameters: [55858397233]&lt;BR /&gt;
20180305 06:10:43,848 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499545} Types: [java.lang.Long]&lt;BR /&gt;
20180305 06:10:43,856 EST DEBUG sql.Connection [WorkflowManager_10027887_55858397233_55868440408_2000]  - {conn-11499546} Connection&lt;BR /&gt;
20180305 06:10:43,856 EST DEBUG sql.Connection [WorkflowManager_10027887_55858397233_55868440408_2000]  - {conn-11499546} Preparing Call: { call SA_TAO_AIP_OPT_TEMPLATE_PKG.get_portf_strtgy_ovrrde(?,?) }&lt;BR /&gt;
20180305 06:10:43,856 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499547} Executing Statement: { call SA_TAO_AIP_OPT_TEMPLATE_PKG.get_portf_strtgy_ovrrde(?,?) }&lt;BR /&gt;
20180305 06:10:43,856 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499547} Parameters: [55868440408]&lt;BR /&gt;
20180305 06:10:43,856 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499547} Types: [java.lang.Long]&lt;BR /&gt;
20180305 06:10:43,867 EST DEBUG sql.Connection [WorkflowManager_10027887_55858397233_55868440408_2000]  - {conn-11499548} Connection&lt;BR /&gt;
20180305 06:10:43,867 EST DEBUG sql.Connection [WorkflowManager_10027887_55858397233_55868440408_2000]  - {conn-11499548} Preparing Call: { call sa_tao_aip_portf_metric_pkg.get_portf_metric_val(?, ?, ?) }&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:18:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/filter-events-based-on-regex-and-index-remaining-props-and/m-p/328984#M61044</guid>
      <dc:creator>sarnagar</dc:creator>
      <dc:date>2020-09-29T18:18:25Z</dc:date>
    </item>
    <item>
      <title>Re: filter events based on regex and index remaining - props and transforms</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/filter-events-based-on-regex-and-index-remaining-props-and/m-p/328985#M61045</link>
      <description>&lt;P&gt;just for my clarification, &lt;CODE&gt;Ex of Logfile&lt;/CODE&gt; which you have provided contain events which you need to filter out only or you have provided all sample events.&lt;BR /&gt;
also try this regex:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;(?m)(Committing all transactions using \(.*\) transaction manager)|(Types:\s\[.*\])|(Preparing Call)|(Clearing Module Context)
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 05 Mar 2018 16:37:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/filter-events-based-on-regex-and-index-remaining-props-and/m-p/328985#M61045</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-03-05T16:37:50Z</dc:date>
    </item>
    <item>
      <title>Re: filter events based on regex and index remaining - props and transforms</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/filter-events-based-on-regex-and-index-remaining-props-and/m-p/328986#M61046</link>
      <description>&lt;P&gt;refer this:&lt;BR /&gt;
&lt;A href="http://docs.splunk.com/Documentation/Splunk/7.0.2/Forwarding/Routeandfilterdatad#Filter_WMI_and_Event_Log_events"&gt;http://docs.splunk.com/Documentation/Splunk/7.0.2/Forwarding/Routeandfilterdatad#Filter_WMI_and_Event_Log_events&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Mar 2018 17:30:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/filter-events-based-on-regex-and-index-remaining-props-and/m-p/328986#M61046</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-03-05T17:30:04Z</dc:date>
    </item>
    <item>
      <title>Re: filter events based on regex and index remaining - props and transforms</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/filter-events-based-on-regex-and-index-remaining-props-and/m-p/328987#M61047</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206320"&gt;@493669&lt;/a&gt; ,&lt;/P&gt;

&lt;P&gt;It still doesnt work. It nulls entire log.&lt;/P&gt;

&lt;P&gt;Here is the complete sample log&lt;/P&gt;

&lt;P&gt;20180305 06:10:43,769 EST DEBUG sql.Connection [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {conn-11499536} Connection&lt;BR /&gt;
20180305 06:10:43,769 EST DEBUG sql.Connection [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {conn-11499536} Preparing Call: { call SA_TAO_AIP_CASH_MGT_TXN_PKG.get_cash_txn_dtl_by_cp_id(?,?) }&lt;BR /&gt;
20180305 06:10:43,769 EST DEBUG sql.PreparedStatement [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {pstm-11499537} Executing Statement: { call SA_TAO_AIP_CASH_MGT_TXN_PKG.get_cash_txn_dtl_by_cp_id(?,?) }&lt;BR /&gt;
20180305 06:10:43,769 EST DEBUG sql.PreparedStatement [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {pstm-11499537} Parameters: [55858397233]&lt;BR /&gt;
20180305 06:10:43,769 EST DEBUG sql.PreparedStatement [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {pstm-11499537} Types: [java.lang.Long]&lt;BR /&gt;
20180305 06:10:43,774 EST DEBUG sql.Connection [WorkflowManager_10027887_55656942908_55666096052_3006]  - {conn-11499538} Connection&lt;BR /&gt;
20180305 06:10:43,774 EST DEBUG sql.Connection [WorkflowManager_10027887_55656942908_55666096052_3006]  - {conn-11499538} Preparing Call: { call SA_TAO_AIP_COMMON_PKG.GET_PORTF_INSTANCE_LOTS(?, ?) }&lt;BR /&gt;
20180305 06:10:43,774 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55656942908_55666096052_3006]  - {pstm-11499539} Executing Statement: { call SA_TAO_AIP_COMMON_PKG.GET_PORTF_INSTANCE_LOTS(?, ?) }&lt;BR /&gt;
20180305 06:10:43,774 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55656942908_55666096052_3006]  - {pstm-11499539} Parameters: [398207947]&lt;BR /&gt;
20180305 06:10:43,774 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55656942908_55666096052_3006]  - {pstm-11499539} Types: [java.lang.Long]&lt;BR /&gt;
20180305 06:10:43,791 EST INFO  domain.CashDomain [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - Available Cash for [investablePortfolioId=55868440408, sleeve=ROP, lot=INITIAL, withLiq=false] is: 1219.5500000 &lt;BR /&gt;
20180305 06:10:43,791 EST DEBUG sql.Connection [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {conn-11499540} Connection&lt;BR /&gt;
20180305 06:10:43,791 EST DEBUG sql.Connection [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {conn-11499540} Preparing Call: { ? = call sa_tao_aip_parameter_pkg.get_ip_portf_param_value(?, ?) }&lt;BR /&gt;
20180305 06:10:43,791 EST DEBUG sql.PreparedStatement [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {pstm-11499541} Executing Statement: { ? = call sa_tao_aip_parameter_pkg.get_ip_portf_param_value(?, ?) }&lt;BR /&gt;
20180305 06:10:43,791 EST DEBUG sql.PreparedStatement [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {pstm-11499541} Parameters: [CASH_TXN_THRESHOLD_DAYS, 55868440408]&lt;BR /&gt;
20180305 06:10:43,791 EST DEBUG sql.PreparedStatement [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {pstm-11499541} Types: [java.lang.String, java.lang.Long]&lt;BR /&gt;
20180305 06:10:43,801 EST INFO  domain.CashDomain [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - Cash transaction threshold days value for [investablePortfolioId=55868440408] is: 60&lt;BR /&gt;
20180305 06:10:43,802 EST DEBUG sql.Connection [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {conn-11499542} Connection&lt;BR /&gt;
20180305 06:10:43,802 EST DEBUG sql.Connection [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {conn-11499542} Preparing Call: { call sa_tao_aip_portf_metric_pkg.ins_portf_metric_val(?) }&lt;BR /&gt;
20180305 06:10:43,802 EST DEBUG sql.PreparedStatement [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {pstm-11499543} Executing Statement: { call sa_tao_aip_portf_metric_pkg.ins_portf_metric_val(?) }&lt;BR /&gt;
20180305 06:10:43,802 EST DEBUG sql.PreparedStatement [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {pstm-11499543} Parameters: [oracle.sql.ARRAY@10b46d2d]&lt;BR /&gt;
20180305 06:10:43,802 EST DEBUG sql.PreparedStatement [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - {pstm-11499543} Types: [oracle.sql.ARRAY]&lt;BR /&gt;
20180305 06:10:43,829 EST INFO  workflow.TransactionalWorkflowOperation [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  - Returning to Workflow manager, returnCode[0]&lt;BR /&gt;
20180305 06:10:43,829 EST INFO  workflow.TransactionalWorkflowOperation [PreOptPortfolioScores_10027887_55858397233_55868440408_8001]  -  ---------- Committing all transactions using (workflowTransaction) transaction manager ---------- &lt;BR /&gt;
20180305 06:10:43,848 EST DEBUG sql.Connection [WorkflowManager_10027887_55858397233_55868440408_2000]  - {conn-11499544} Connection&lt;BR /&gt;
20180305 06:10:43,848 EST DEBUG sql.Connection [WorkflowManager_10027887_55858397233_55868440408_2000]  - {conn-11499544} Preparing Call: { call SA_TAO_AIP_PORTFOLIO_PKG.GET_ALL_INV_PORTF_FOR_CLIENT(?, ?) }&lt;BR /&gt;
20180305 06:10:43,848 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499545} Executing Statement: { call SA_TAO_AIP_PORTFOLIO_PKG.GET_ALL_INV_PORTF_FOR_CLIENT(?, ?) }&lt;BR /&gt;
20180305 06:10:43,848 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499545} Parameters: [55858397233]&lt;BR /&gt;
20180305 06:10:43,848 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499545} Types: [java.lang.Long]&lt;BR /&gt;
20180305 06:10:43,856 EST DEBUG sql.Connection [WorkflowManager_10027887_55858397233_55868440408_2000]  - {conn-11499546} Connection&lt;BR /&gt;
20180305 06:10:43,856 EST DEBUG sql.Connection [WorkflowManager_10027887_55858397233_55868440408_2000]  - {conn-11499546} Preparing Call: { call SA_TAO_AIP_OPT_TEMPLATE_PKG.get_portf_strtgy_ovrrde(?,?) }&lt;BR /&gt;
20180305 06:10:43,856 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499547} Executing Statement: { call SA_TAO_AIP_OPT_TEMPLATE_PKG.get_portf_strtgy_ovrrde(?,?) }&lt;BR /&gt;
20180305 06:10:43,856 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499547} Parameters: [55868440408]&lt;BR /&gt;
20180305 06:10:43,856 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499547} Types: [java.lang.Long]&lt;BR /&gt;
20180305 06:10:43,867 EST DEBUG sql.Connection [WorkflowManager_10027887_55858397233_55868440408_2000]  - {conn-11499548} Connection&lt;BR /&gt;
20180305 06:10:43,867 EST DEBUG sql.Connection [WorkflowManager_10027887_55858397233_55868440408_2000]  - {conn-11499548} Preparing Call: { call sa_tao_aip_portf_metric_pkg.get_portf_metric_val(?, ?, ?) }&lt;BR /&gt;
20180305 06:10:43,867 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499549} Executing Statement: { call sa_tao_aip_portf_metric_pkg.get_portf_metric_val(?, ?, ?) }&lt;BR /&gt;
20180305 06:10:43,867 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499549} Parameters: [10027887, 55868440408]&lt;BR /&gt;
20180305 06:10:43,867 EST DEBUG sql.PreparedStatement [WorkflowManager_10027887_55858397233_55868440408_2000]  - {pstm-11499549} Types: [java.lang.Long, java.lang.Long]&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 18:19:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/filter-events-based-on-regex-and-index-remaining-props-and/m-p/328987#M61047</guid>
      <dc:creator>sarnagar</dc:creator>
      <dc:date>2020-09-29T18:19:07Z</dc:date>
    </item>
    <item>
      <title>Re: filter events based on regex and index remaining - props and transforms</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/filter-events-based-on-regex-and-index-remaining-props-and/m-p/328988#M61048</link>
      <description>&lt;P&gt;are you using standalone or clustered environment?&lt;BR /&gt;
and where you have placed props.conf in Heavy forwarder or indexer?&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 15:47:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/filter-events-based-on-regex-and-index-remaining-props-and/m-p/328988#M61048</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-03-06T15:47:26Z</dc:date>
    </item>
    <item>
      <title>Re: filter events based on regex and index remaining - props and transforms</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/filter-events-based-on-regex-and-index-remaining-props-and/m-p/328989#M61049</link>
      <description>&lt;P&gt;I'm using clustered env.&lt;BR /&gt;
I've placed props n transforms on heavy forwarder&lt;/P&gt;</description>
      <pubDate>Tue, 06 Mar 2018 16:00:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/filter-events-based-on-regex-and-index-remaining-props-and/m-p/328989#M61049</guid>
      <dc:creator>sarnagar</dc:creator>
      <dc:date>2018-03-06T16:00:26Z</dc:date>
    </item>
    <item>
      <title>Re: filter events based on regex and index remaining - props and transforms</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/filter-events-based-on-regex-and-index-remaining-props-and/m-p/328990#M61050</link>
      <description>&lt;P&gt;ok then try this in props.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[sourcetypename]
TRANSFORMS-null= setnull
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;in transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[setnull]
REGEX =(?i)Committing\sall\stransactions\susing\s\(.*\)\stransaction\smanager
DEST_KEY = queue
FORMAT = nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;try this and if it works then add remaining regex...&lt;/P&gt;

&lt;P&gt;after making changes restart forwarder&lt;/P&gt;</description>
      <pubDate>Wed, 07 Mar 2018 17:57:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/filter-events-based-on-regex-and-index-remaining-props-and/m-p/328990#M61050</guid>
      <dc:creator>493669</dc:creator>
      <dc:date>2018-03-07T17:57:23Z</dc:date>
    </item>
  </channel>
</rss>

