<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: IIS filter transform not processing when forwarded from universal forwarder, but does with manual file input? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/IIS-filter-transform-not-processing-when-forwarded-from/m-p/369058#M67012</link>
    <description>&lt;P&gt;This works as is. Just have to make sure to place the file in the right spot, restart the UF and &lt;EM&gt;WAIT&lt;/EM&gt;. It took a little while for events with the correct filter to come in. I'm guessing there was a queue somewhere between sending to Splunk and applying the props/transforms.&lt;/P&gt;</description>
    <pubDate>Wed, 25 Oct 2017 22:36:10 GMT</pubDate>
    <dc:creator>JacobCarrell</dc:creator>
    <dc:date>2017-10-25T22:36:10Z</dc:date>
    <item>
      <title>IIS filter transform not processing when forwarded from universal forwarder, but does with manual file input?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/IIS-filter-transform-not-processing-when-forwarded-from/m-p/369057#M67011</link>
      <description>&lt;P&gt;I've found many entries on the subject of filtering IIS logs, with people saying X has worked. However, I'm not able to get it fully working. If I copy an IIS log that should be filtered to the server and import it manually it works (as far as I can tell, I only went to preview) but if I use a UF from a server 2003 (so older UF version) box, to the Splunk server on windows 2012 (6.6.3), it doesn't get filtered. Any help here? &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Props.conf:
[iis]
TRANSFORMS-ignoredpages= iis_ignoredpages


Transforms.conf:
[iis_ignoredpages]
#SOURCE_KEY=field:cs_uri_stem
REGEX=(Page1|Page2)
DEST_KEY= queue
FORMAT=nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Page1 and Page2 are only part of the cs-uri-stem (that's its name in the IIS logs, but Splunk seems to turn it into cs_uri_stem), instead they're like companyname.product.page1/service.asmx or companyname.product/page2.asmx&lt;/P&gt;

&lt;P&gt;I've tried placing the props and transforms files on both the system/local directory of the UF and the Splunk receiver, restarted both and it continued to process the unwanted pages. &lt;/P&gt;

&lt;P&gt;I understand that it looks like UF itself can't filter these lines, but that it processes them sufficiently to get past props and transforms on the Splunk machine. &lt;STRONG&gt;I assume there's a way I can make Universal Fowarder send the logs RAW and the Spunk box will go "OH, W3C, process normally," but how do I do that?&lt;/STRONG&gt; &lt;/P&gt;

&lt;P&gt;---- Less relevant ----&lt;BR /&gt;
Filtering out these pages is absolutely critical as they're hundreds of thousands of internal calls that would spam the Splunk logs, and overwhelm our 500mb/day limit that I need to stay under for proof of concept. &lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 16:02:59 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/IIS-filter-transform-not-processing-when-forwarded-from/m-p/369057#M67011</guid>
      <dc:creator>JacobCarrell</dc:creator>
      <dc:date>2020-09-29T16:02:59Z</dc:date>
    </item>
    <item>
      <title>Re: IIS filter transform not processing when forwarded from universal forwarder, but does with manual file input?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/IIS-filter-transform-not-processing-when-forwarded-from/m-p/369058#M67012</link>
      <description>&lt;P&gt;This works as is. Just have to make sure to place the file in the right spot, restart the UF and &lt;EM&gt;WAIT&lt;/EM&gt;. It took a little while for events with the correct filter to come in. I'm guessing there was a queue somewhere between sending to Splunk and applying the props/transforms.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2017 22:36:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/IIS-filter-transform-not-processing-when-forwarded-from/m-p/369058#M67012</guid>
      <dc:creator>JacobCarrell</dc:creator>
      <dc:date>2017-10-25T22:36:10Z</dc:date>
    </item>
  </channel>
</rss>

