<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Issue sending events to nullQueue. in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Issue-sending-events-to-nullQueue/m-p/466519#M80366</link>
    <description>&lt;PRE&gt;&lt;CODE&gt;2020-05-28T14:19:34-04:00 abuhnasfiler01.euc.ppg.com 1 2020-05-28T21:19:34.322906+03:00 abuhnasfiler01 nasuni.7e485ffc-4467-468f-b298-1 11064 8103704790 - {"to_gid": null, "event_type": "AUDIT_SETXATTR", "sequence": 63553546, "pid": 18010, "groupname": "PPGEUR\\domain users", "result": 0, "uid": 80399113, "is_dir": false, "size": null, "timestamp": 1590689974.2567756, "proto": "AUDIT_PROTO_CIFS", "ipaddr": "10.174.100.2", "ts": null, "to": null, "gid": 80001513, "filesize": null, "to_uid": null, "sid": "S-1-5-21-1570054266-39153565-926709054-398113", "tid": 18010, "username": "PPGEUR\\m00990", "path_timestamp": 0.0, "datasync": null, "volume": "7e485ffc-4467-468f-b298-17e52bab439b_0", "offset": null, "path": "/now/Groups/Common/Sales_Tinting/Silviu/Qlik/2015/Ianuarie 2015/Primite/Rapoarte/Total Decembrie 2014/pigment_67559.csv", "newpath": null, "shared_link_key": null, "resource": "BUHGroups$", "name": "user.DOSATTRIB", "length": null, "flags": null, "mode": null}
event_type = SETXATTReventtype = nix-all-logshost = abuhnasfiler01.euc.ppg.comindex = nasuni_auditingsource = /syslog-ng/nasuni/abuhnasfiler01.euc.ppg.com/2020-05-28.logsourcetype = nasuni
&lt;/CODE&gt;&lt;/PRE&gt;</description>
    <pubDate>Thu, 28 May 2020 18:29:37 GMT</pubDate>
    <dc:creator>bnichols024</dc:creator>
    <dc:date>2020-05-28T18:29:37Z</dc:date>
    <item>
      <title>Issue sending events to nullQueue.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-sending-events-to-nullQueue/m-p/466517#M80364</link>
      <description>&lt;P&gt;I'm having some issues sending specific events to &lt;CODE&gt;nullQueue&lt;/CODE&gt;. I want all events from a specific source with the &lt;CODE&gt;event_type=SETXATTR&lt;/CODE&gt; sent to &lt;CODE&gt;nullqueue&lt;/CODE&gt;. I have this in my props and transforms files that is currently not working:&lt;/P&gt;
&lt;P&gt;Props.conf&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;[source::/syslog-ng/nasuni/*/*.log]
TRANSFORMS-null= setnull
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;Transforms.conf&lt;/P&gt;
&lt;PRE&gt;&lt;CODE&gt;[setnull]
REGEX = (?&amp;lt;event_type&amp;gt;SETXATTR)
DEST_KEY = queue
FORMAT = nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;
&lt;P&gt;Also, where exactly on the indexers should these be? I've read some say to put in the &lt;CODE&gt;$SPLUNK_HOME/etc/system/local&lt;/CODE&gt; folder and others say to put in the &lt;CODE&gt;$SPLUNK_HOME/etc/apps/myapp/local&lt;/CODE&gt; folder.&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Sun, 07 Jun 2020 01:04:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-sending-events-to-nullQueue/m-p/466517#M80364</guid>
      <dc:creator>bnichols024</dc:creator>
      <dc:date>2020-06-07T01:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: Issue sending events to nullQueue.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-sending-events-to-nullQueue/m-p/466518#M80365</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;Please check the regex whether it's capturing the data as needed. Please give us a sample event to work it out for you.&lt;BR /&gt;
Your props and transforms are correct&lt;BR /&gt;
The best practice is to put the conf in your app directory  &lt;CODE&gt;$SPLUNK_HOME/etc/apps/myapp/local&lt;/CODE&gt;.&lt;/P&gt;</description>
      <pubDate>Thu, 28 May 2020 18:03:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-sending-events-to-nullQueue/m-p/466518#M80365</guid>
      <dc:creator>dindu</dc:creator>
      <dc:date>2020-05-28T18:03:13Z</dc:date>
    </item>
    <item>
      <title>Re: Issue sending events to nullQueue.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-sending-events-to-nullQueue/m-p/466519#M80366</link>
      <description>&lt;PRE&gt;&lt;CODE&gt;2020-05-28T14:19:34-04:00 abuhnasfiler01.euc.ppg.com 1 2020-05-28T21:19:34.322906+03:00 abuhnasfiler01 nasuni.7e485ffc-4467-468f-b298-1 11064 8103704790 - {"to_gid": null, "event_type": "AUDIT_SETXATTR", "sequence": 63553546, "pid": 18010, "groupname": "PPGEUR\\domain users", "result": 0, "uid": 80399113, "is_dir": false, "size": null, "timestamp": 1590689974.2567756, "proto": "AUDIT_PROTO_CIFS", "ipaddr": "10.174.100.2", "ts": null, "to": null, "gid": 80001513, "filesize": null, "to_uid": null, "sid": "S-1-5-21-1570054266-39153565-926709054-398113", "tid": 18010, "username": "PPGEUR\\m00990", "path_timestamp": 0.0, "datasync": null, "volume": "7e485ffc-4467-468f-b298-17e52bab439b_0", "offset": null, "path": "/now/Groups/Common/Sales_Tinting/Silviu/Qlik/2015/Ianuarie 2015/Primite/Rapoarte/Total Decembrie 2014/pigment_67559.csv", "newpath": null, "shared_link_key": null, "resource": "BUHGroups$", "name": "user.DOSATTRIB", "length": null, "flags": null, "mode": null}
event_type = SETXATTReventtype = nix-all-logshost = abuhnasfiler01.euc.ppg.comindex = nasuni_auditingsource = /syslog-ng/nasuni/abuhnasfiler01.euc.ppg.com/2020-05-28.logsourcetype = nasuni
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 28 May 2020 18:29:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-sending-events-to-nullQueue/m-p/466519#M80366</guid>
      <dc:creator>bnichols024</dc:creator>
      <dc:date>2020-05-28T18:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: Issue sending events to nullQueue.</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Issue-sending-events-to-nullQueue/m-p/466520#M80367</link>
      <description>&lt;P&gt;Hi bnichols024, &lt;/P&gt;

&lt;P&gt;I think your REGEX is incorrect....you made the capture group a named group called event_type, rather than looking for the string. &lt;/P&gt;

&lt;P&gt;Try this: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[setnull]
REGEX = (event_type = SETXATTR)
DEST_KEY = queue
FORMAT = nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 29 May 2020 14:05:07 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Issue-sending-events-to-nullQueue/m-p/466520#M80367</guid>
      <dc:creator>darrenfuller</dc:creator>
      <dc:date>2020-05-29T14:05:07Z</dc:date>
    </item>
  </channel>
</rss>

