<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I filter logs from being indexed in Splunk Cloud in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-filter-logs-from-being-indexed-in-Splunk-Cloud/m-p/375773#M68052</link>
    <description>&lt;P&gt;Thanks for the reply. But I specify it few time in my question and bolded it even. I need solution in &lt;STRONG&gt;Splunk Cloud&lt;/STRONG&gt; not in the level of UF or HF(Heavy forwarder).&lt;/P&gt;</description>
    <pubDate>Sun, 06 May 2018 15:47:56 GMT</pubDate>
    <dc:creator>eddiemashayev</dc:creator>
    <dc:date>2018-05-06T15:47:56Z</dc:date>
    <item>
      <title>How can I filter logs from being indexed in Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-filter-logs-from-being-indexed-in-Splunk-Cloud/m-p/375771#M68050</link>
      <description>&lt;P&gt;Hey all,&lt;/P&gt;

&lt;P&gt;I want to filter logs before they are being indexed in &lt;STRONG&gt;Splunk Cloud&lt;/STRONG&gt; for example, I want to filter all logs with &lt;CODE&gt;host="test*"&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;How can I do that in Splunk Cloud?&lt;/P&gt;</description>
      <pubDate>Sun, 06 May 2018 14:47:57 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-filter-logs-from-being-indexed-in-Splunk-Cloud/m-p/375771#M68050</guid>
      <dc:creator>eddiemashayev</dc:creator>
      <dc:date>2018-05-06T14:47:57Z</dc:date>
    </item>
    <item>
      <title>Re: How can I filter logs from being indexed in Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-filter-logs-from-being-indexed-in-Splunk-Cloud/m-p/375772#M68051</link>
      <description>&lt;P&gt;You can discard the data via nullQueue on your Intermediate/Heavy forwarder...&lt;/P&gt;

&lt;P&gt;&lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 06 May 2018 15:29:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-filter-logs-from-being-indexed-in-Splunk-Cloud/m-p/375772#M68051</guid>
      <dc:creator>prakash007</dc:creator>
      <dc:date>2018-05-06T15:29:41Z</dc:date>
    </item>
    <item>
      <title>Re: How can I filter logs from being indexed in Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-filter-logs-from-being-indexed-in-Splunk-Cloud/m-p/375773#M68052</link>
      <description>&lt;P&gt;Thanks for the reply. But I specify it few time in my question and bolded it even. I need solution in &lt;STRONG&gt;Splunk Cloud&lt;/STRONG&gt; not in the level of UF or HF(Heavy forwarder).&lt;/P&gt;</description>
      <pubDate>Sun, 06 May 2018 15:47:56 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-filter-logs-from-being-indexed-in-Splunk-Cloud/m-p/375773#M68052</guid>
      <dc:creator>eddiemashayev</dc:creator>
      <dc:date>2018-05-06T15:47:56Z</dc:date>
    </item>
    <item>
      <title>Re: How can I filter logs from being indexed in Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-filter-logs-from-being-indexed-in-Splunk-Cloud/m-p/375774#M68053</link>
      <description>&lt;P&gt;I guess it should be enabled with props and transforms on the indexers in Splunk Cloud(may be a support ticket)&lt;/P&gt;

&lt;P&gt;&lt;A href="https://www.youtube.com/watch?v=RJAaTyFHKeo&amp;amp;index=1&amp;amp;list=PL7zWAA-DF0k9xVLrl1j-lk2F74Ge3EgCZ"&gt;https://www.youtube.com/watch?v=RJAaTyFHKeo&amp;amp;index=1&amp;amp;list=PL7zWAA-DF0k9xVLrl1j-lk2F74Ge3EgCZ&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 06 May 2018 16:37:32 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-filter-logs-from-being-indexed-in-Splunk-Cloud/m-p/375774#M68053</guid>
      <dc:creator>prakash007</dc:creator>
      <dc:date>2018-05-06T16:37:32Z</dc:date>
    </item>
    <item>
      <title>Re: How can I filter logs from being indexed in Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-filter-logs-from-being-indexed-in-Splunk-Cloud/m-p/375775#M68054</link>
      <description>&lt;P&gt;You need to create an app for your Indexers to send the selected events to &lt;CODE&gt;nullQueue&lt;/CODE&gt; then you need to open a support case to submit it to for vetting, which can take a while, but it is getting better.&lt;/P&gt;</description>
      <pubDate>Sun, 06 May 2018 18:05:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-filter-logs-from-being-indexed-in-Splunk-Cloud/m-p/375775#M68054</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-05-06T18:05:38Z</dc:date>
    </item>
    <item>
      <title>Re: How can I filter logs from being indexed in Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-filter-logs-from-being-indexed-in-Splunk-Cloud/m-p/375776#M68055</link>
      <description>&lt;P&gt;Why this is so complicated? Just want to filter logs before indexing, it should be very simple. Are you sure there is no other way?&lt;/P&gt;</description>
      <pubDate>Mon, 07 May 2018 08:46:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-filter-logs-from-being-indexed-in-Splunk-Cloud/m-p/375776#M68055</guid>
      <dc:creator>eddiemashayev</dc:creator>
      <dc:date>2018-05-07T08:46:38Z</dc:date>
    </item>
    <item>
      <title>Re: How can I filter logs from being indexed in Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-filter-logs-from-being-indexed-in-Splunk-Cloud/m-p/375777#M68056</link>
      <description>&lt;P&gt;I didn't find in Splunk App for existing application which do the same. Maybe there is some app that have this functionality?&lt;/P&gt;</description>
      <pubDate>Mon, 07 May 2018 08:57:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-filter-logs-from-being-indexed-in-Splunk-Cloud/m-p/375777#M68056</guid>
      <dc:creator>eddiemashayev</dc:creator>
      <dc:date>2018-05-07T08:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: How can I filter logs from being indexed in Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-filter-logs-from-being-indexed-in-Splunk-Cloud/m-p/375778#M68057</link>
      <description>&lt;P&gt;You are overestimating what is an app; it is just a package of configuration files.  Create your files, package them as an app, submit them by case to be installed on your indexers.&lt;/P&gt;</description>
      <pubDate>Mon, 07 May 2018 11:15:34 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-filter-logs-from-being-indexed-in-Splunk-Cloud/m-p/375778#M68057</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-05-07T11:15:34Z</dc:date>
    </item>
    <item>
      <title>Re: How can I filter logs from being indexed in Splunk Cloud</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-can-I-filter-logs-from-being-indexed-in-Splunk-Cloud/m-p/375779#M68058</link>
      <description>&lt;P&gt;Thanks for clarification.&lt;BR /&gt;
I do see many documentation on how to do it on premise, but I'm working on &lt;STRONG&gt;Splunk Cloud&lt;/STRONG&gt; and I can't access to the instance to change &lt;CODE&gt;/opt/Splunk&lt;/CODE&gt; files.&lt;/P&gt;

&lt;P&gt;Do you know for any good documentation for Splunk Cloud? &lt;/P&gt;</description>
      <pubDate>Mon, 07 May 2018 14:07:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-can-I-filter-logs-from-being-indexed-in-Splunk-Cloud/m-p/375779#M68058</guid>
      <dc:creator>eddiemashayev</dc:creator>
      <dc:date>2018-05-07T14:07:58Z</dc:date>
    </item>
  </channel>
</rss>

