<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: What is the best way to filter events at Heavy Forwarder level? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-filter-events-at-Heavy-Forwarder-level/m-p/345094#M63438</link>
    <description>&lt;P&gt;Unfortunately I'm having to route through it. Have to follow the implemented design. Any advice would be appreciated. &lt;/P&gt;</description>
    <pubDate>Tue, 25 Apr 2017 04:37:28 GMT</pubDate>
    <dc:creator>aoliullah</dc:creator>
    <dc:date>2017-04-25T04:37:28Z</dc:date>
    <item>
      <title>What is the best way to filter events at Heavy Forwarder level?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-filter-events-at-Heavy-Forwarder-level/m-p/345092#M63436</link>
      <description>&lt;P&gt;Hi.&lt;/P&gt;

&lt;P&gt;I am trying to send logs from a bunch of Universal Forwarders (UF) to a Heavy Forwarder which will then forward it to a SOC (managed service - we have a syslog receiver onsite). &lt;/P&gt;

&lt;P&gt;Currently, all the logs are being indexed into Splunk but I am planning to edit the outputs stanza on the UFs by adding another group with the Heavy Forwarder's IP address,  so that it creates a data clone and then I can filter out the required data at the HF before sending it SOC.&lt;/P&gt;

&lt;P&gt;I am trying to figure out the best method of filtering this data. Basically, these UFs are monitoring lots of application data in addition to the local event logs and other security logs. I am only interested in the local event logs (both Windows and Unix) and security logs and want to get rid of all other logs (nullQueue).&lt;/P&gt;

&lt;P&gt;What would be the best way to achieve this? Should I filter using the source (i.e. Whitelisting a number of sources)? So that only the whitelisted sources are forwarded by the HF to the SOC and all the rest from the data clone goes to nullqueue.&lt;/P&gt;

&lt;P&gt;Would highly appreciate if someone could show me a config example. &lt;/P&gt;

&lt;P&gt;Thanks in advance?&lt;/P&gt;</description>
      <pubDate>Mon, 24 Apr 2017 20:41:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-filter-events-at-Heavy-Forwarder-level/m-p/345092#M63436</guid>
      <dc:creator>aoliullah</dc:creator>
      <dc:date>2017-04-24T20:41:22Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to filter events at Heavy Forwarder level?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-filter-events-at-Heavy-Forwarder-level/m-p/345093#M63437</link>
      <description>&lt;P&gt;hello aoliullah,&lt;BR /&gt;
are the HF a requirements? you can filter at the UF level or Indexer level. will recommend against HF unless you really have to have it.&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2017 01:36:21 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-filter-events-at-Heavy-Forwarder-level/m-p/345093#M63437</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-04-25T01:36:21Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to filter events at Heavy Forwarder level?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-filter-events-at-Heavy-Forwarder-level/m-p/345094#M63438</link>
      <description>&lt;P&gt;Unfortunately I'm having to route through it. Have to follow the implemented design. Any advice would be appreciated. &lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2017 04:37:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-filter-events-at-Heavy-Forwarder-level/m-p/345094#M63438</guid>
      <dc:creator>aoliullah</dc:creator>
      <dc:date>2017-04-25T04:37:28Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to filter events at Heavy Forwarder level?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-filter-events-at-Heavy-Forwarder-level/m-p/345095#M63439</link>
      <description>&lt;P&gt;If you must use the Heavy Forwarder,&lt;BR /&gt;
use props and transforms as explained in docs: &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad&lt;/A&gt;&lt;BR /&gt;
also many more answers in this portal, look for filter, route, props, transforms, etc.&lt;BR /&gt;
hope it helps&lt;/P&gt;</description>
      <pubDate>Tue, 25 Apr 2017 11:55:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-filter-events-at-Heavy-Forwarder-level/m-p/345095#M63439</guid>
      <dc:creator>adonio</dc:creator>
      <dc:date>2017-04-25T11:55:10Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to filter events at Heavy Forwarder level?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-filter-events-at-Heavy-Forwarder-level/m-p/669321#M112223</link>
      <description>&lt;P&gt;I want to filter the palo logs at the forwarder level by looking at the packet before indexing( licensing) based certain condition like... zone, firewall name(enterprise) etc&lt;/P&gt;&lt;P&gt;The logs comes to both our UF &amp;amp; HF, what is the best way to achieve it.&lt;/P&gt;&lt;P&gt;Was looking into a few doc suggesting to apply ingest eval, is that feasible?&lt;/P&gt;&lt;P&gt;Can anyone please help me with this.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 12:29:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-filter-events-at-Heavy-Forwarder-level/m-p/669321#M112223</guid>
      <dc:creator>NeharikaVats</dc:creator>
      <dc:date>2023-11-21T12:29:38Z</dc:date>
    </item>
    <item>
      <title>Re: What is the best way to filter events at Heavy Forwarder level?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-filter-events-at-Heavy-Forwarder-level/m-p/669327#M112224</link>
      <description>&lt;P&gt;You're much more likely to get a relevant answer if you post a new question instead of digging up an old thread (especially that old).&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 13:35:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/What-is-the-best-way-to-filter-events-at-Heavy-Forwarder-level/m-p/669327#M112224</guid>
      <dc:creator>PickleRick</dc:creator>
      <dc:date>2023-11-21T13:35:26Z</dc:date>
    </item>
  </channel>
</rss>

