<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why am I still seeing debug logs in the Splunk heavy forwarder filtering? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-still-seeing-debug-logs-in-the-Splunk-heavy-forwarder/m-p/354093#M64777</link>
    <description>&lt;P&gt;This will only affect the new incoming messages (any already ingested data would still showup in the search results). What does you DEBUG event look like? Can share a sample or two?&lt;/P&gt;</description>
    <pubDate>Fri, 20 Apr 2018 20:31:09 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2018-04-20T20:31:09Z</dc:date>
    <item>
      <title>Why am I still seeing debug logs in the Splunk heavy forwarder filtering?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-still-seeing-debug-logs-in-the-Splunk-heavy-forwarder/m-p/354090#M64774</link>
      <description>&lt;P&gt;I have set the following on transforms.conf and props.conf but I still see DEBUG logs in my search. what did I miss&lt;/P&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#Remove: DEBUG
[null_kube_DEBUG]
REGEX = (DEBUG)
DEST_KEY=queue
FORMAT=nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;#### kube ################################
[source::kube.var.log.containers.*]
TRANSFORMS-null = null_kube_DEBUG
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 20 Apr 2018 17:32:01 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-still-seeing-debug-logs-in-the-Splunk-heavy-forwarder/m-p/354090#M64774</guid>
      <dc:creator>raindrop18</dc:creator>
      <dc:date>2018-04-20T17:32:01Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I still seeing debug logs in the Splunk heavy forwarder filtering?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-still-seeing-debug-logs-in-the-Splunk-heavy-forwarder/m-p/354091#M64775</link>
      <description>&lt;P&gt;Did you restart the HF?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 18:08:36 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-still-seeing-debug-logs-in-the-Splunk-heavy-forwarder/m-p/354091#M64775</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2018-04-20T18:08:36Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I still seeing debug logs in the Splunk heavy forwarder filtering?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-still-seeing-debug-logs-in-the-Splunk-heavy-forwarder/m-p/354092#M64776</link>
      <description>&lt;P&gt;yes I did &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 18:54:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-still-seeing-debug-logs-in-the-Splunk-heavy-forwarder/m-p/354092#M64776</guid>
      <dc:creator>raindrop18</dc:creator>
      <dc:date>2018-04-20T18:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I still seeing debug logs in the Splunk heavy forwarder filtering?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-still-seeing-debug-logs-in-the-Splunk-heavy-forwarder/m-p/354093#M64777</link>
      <description>&lt;P&gt;This will only affect the new incoming messages (any already ingested data would still showup in the search results). What does you DEBUG event look like? Can share a sample or two?&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 20:31:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-still-seeing-debug-logs-in-the-Splunk-heavy-forwarder/m-p/354093#M64777</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-04-20T20:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I still seeing debug logs in the Splunk heavy forwarder filtering?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-still-seeing-debug-logs-in-the-Splunk-heavy-forwarder/m-p/354094#M64778</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;2018-04-20 20:36:35 DEBUG NetworkClient:627 - Initiating connection to node -1 at myserver1.net:9092.\n
2018-04-20 20:36:35 DEBUG NetworkClient:767 - Initialize connection to node -1 for sending metadata request\n
2018-04-20 20:36:35 DEBUG NetworkClient:570 - Node -3 disconnected.\n
2018-04-20 20:36:35 DEBUG NetworkClient:627 - Initiating connection to node -1 at myserver1.net:9092.\n
2018-04-20 20:36:35 DEBUG NetworkClient:767 - Initialize connection to node -1 for sending metadata request\n
2018-04-20 20:36:35 DEBUG NetworkClient:570 - Node -2 disconnected.\n
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 20 Apr 2018 20:38:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-still-seeing-debug-logs-in-the-Splunk-heavy-forwarder/m-p/354094#M64778</guid>
      <dc:creator>raindrop18</dc:creator>
      <dc:date>2018-04-20T20:38:38Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I still seeing debug logs in the Splunk heavy forwarder filtering?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-still-seeing-debug-logs-in-the-Splunk-heavy-forwarder/m-p/354095#M64779</link>
      <description>&lt;P&gt;this is newly ingested data.&lt;/P&gt;</description>
      <pubDate>Fri, 20 Apr 2018 20:39:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-still-seeing-debug-logs-in-the-Splunk-heavy-forwarder/m-p/354095#M64779</guid>
      <dc:creator>raindrop18</dc:creator>
      <dc:date>2018-04-20T20:39:12Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I still seeing debug logs in the Splunk heavy forwarder filtering?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-still-seeing-debug-logs-in-the-Splunk-heavy-forwarder/m-p/354096#M64780</link>
      <description>&lt;P&gt;Can you try to use in props.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; [null_kube_DEBUG]
 REGEX = DEBUG
 DEST_KEY=queue
 FORMAT=nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Mon, 23 Apr 2018 04:27:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-still-seeing-debug-logs-in-the-Splunk-heavy-forwarder/m-p/354096#M64780</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-04-23T04:27:27Z</dc:date>
    </item>
    <item>
      <title>Re: Why am I still seeing debug logs in the Splunk heavy forwarder filtering?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-still-seeing-debug-logs-in-the-Splunk-heavy-forwarder/m-p/354097#M64781</link>
      <description>&lt;P&gt;thanks for the response, but still not filtering DEBUG.  is there any difference for the logs ingested via http even collector (HEC)? this issue only I got on the logs ingested via HEC,  other logs ingested via UF I don't see this issue.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Apr 2018 14:57:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Why-am-I-still-seeing-debug-logs-in-the-Splunk-heavy-forwarder/m-p/354097#M64781</guid>
      <dc:creator>raindrop18</dc:creator>
      <dc:date>2018-04-23T14:57:03Z</dc:date>
    </item>
  </channel>
</rss>

