<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Manipulate logs in upload in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Manipulate-logs-in-upload/m-p/429854#M75295</link>
    <description>&lt;P&gt;The first part probably can be done using &lt;CODE&gt;SEDCMD&lt;/CODE&gt; in props.conf if you can come up with a regex that matches the lines to remove.&lt;BR /&gt;
The second part, however, is not possible in Splunk.  You'll need to create a scripted input or use a pre-processor such as Cribl (not sure Cribl can do that, though).&lt;/P&gt;</description>
    <pubDate>Wed, 07 Aug 2019 12:36:16 GMT</pubDate>
    <dc:creator>richgalloway</dc:creator>
    <dc:date>2019-08-07T12:36:16Z</dc:date>
    <item>
      <title>Manipulate logs in upload</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Manipulate-logs-in-upload/m-p/429853#M75294</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;
I have logs that have in the top some data that doesn't relevant for me and I would like that it won't appear.&lt;/P&gt;

&lt;H1&gt;This is the data that I would like to remove:&lt;/H1&gt;

&lt;P&gt;Device version: D02.20.33&lt;BR /&gt;
MCFG Version:   Unknown&lt;/P&gt;

&lt;H1&gt;UP TIME:    00:05:24.292&lt;/H1&gt;

&lt;P&gt;emory pool at 0x000000008f000000, size 8 MiB&lt;/P&gt;

&lt;P&gt;also, I have some rows in the log that not include a timestamp and I want to add the same timestamp as the one in the next line. for example, this is the logs:&lt;BR /&gt;
--------- beginning of events&lt;BR /&gt;
01-15 04:17:19.370   453   453 I auditd  : type=2000 audit(0.0:1): initialized&lt;/P&gt;

&lt;P&gt;and I would like that it will be:&lt;BR /&gt;
01-15 04:17:19.370   453   453 --------- beginning of events&lt;BR /&gt;
01-15 04:17:19.370   453   453 I auditd  : type=2000 audit(0.0:1): initialized&lt;/P&gt;

&lt;P&gt;can I do that with Splunk when I'm uploading the logs?&lt;BR /&gt;
Thank you!&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 07:29:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Manipulate-logs-in-upload/m-p/429853#M75294</guid>
      <dc:creator>alisaf</dc:creator>
      <dc:date>2019-08-07T07:29:22Z</dc:date>
    </item>
    <item>
      <title>Re: Manipulate logs in upload</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Manipulate-logs-in-upload/m-p/429854#M75295</link>
      <description>&lt;P&gt;The first part probably can be done using &lt;CODE&gt;SEDCMD&lt;/CODE&gt; in props.conf if you can come up with a regex that matches the lines to remove.&lt;BR /&gt;
The second part, however, is not possible in Splunk.  You'll need to create a scripted input or use a pre-processor such as Cribl (not sure Cribl can do that, though).&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 12:36:16 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Manipulate-logs-in-upload/m-p/429854#M75295</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-08-07T12:36:16Z</dc:date>
    </item>
    <item>
      <title>Re: Manipulate logs in upload</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Manipulate-logs-in-upload/m-p/429855#M75296</link>
      <description>&lt;P&gt;Thank you!&lt;BR /&gt;
Splunk default associates this line to the previous event, maybe there is some option to associate this line with the next event?&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 14:48:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Manipulate-logs-in-upload/m-p/429855#M75296</guid>
      <dc:creator>alisaf</dc:creator>
      <dc:date>2019-08-07T14:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: Manipulate logs in upload</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Manipulate-logs-in-upload/m-p/429856#M75297</link>
      <description>&lt;P&gt;There is no such option.  That's why I said "not possible".&lt;/P&gt;</description>
      <pubDate>Wed, 07 Aug 2019 16:45:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Manipulate-logs-in-upload/m-p/429856#M75297</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-08-07T16:45:15Z</dc:date>
    </item>
    <item>
      <title>Re: Manipulate logs in upload</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Manipulate-logs-in-upload/m-p/429857#M75298</link>
      <description>&lt;P&gt;thanks &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2019 05:49:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Manipulate-logs-in-upload/m-p/429857#M75298</guid>
      <dc:creator>alisaf</dc:creator>
      <dc:date>2019-08-08T05:49:30Z</dc:date>
    </item>
  </channel>
</rss>

