<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Using sedcmd to truncate QPM= in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Using-sedcmd-to-truncate-QPM/m-p/473878#M81376</link>
    <description>&lt;P&gt;Are you looking to truncate part of your raw data or just drop the whole event itself (no indexing)? If it's the latter, I would suggest reading/implementing this:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.1/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.1/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Your sample data and configuration entries will get truncated if you do not format them using "100010" button on top of the text editor in this page (or select and press Ctrl+K).&lt;/P&gt;</description>
    <pubDate>Mon, 09 Sep 2019 13:39:42 GMT</pubDate>
    <dc:creator>somesoni2</dc:creator>
    <dc:date>2019-09-09T13:39:42Z</dc:date>
    <item>
      <title>Using sedcmd to truncate QPM=</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-sedcmd-to-truncate-QPM/m-p/473876#M81374</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;

&lt;P&gt;Wondering if anyone has a solution to an issue I'm having truncating out some values we deem to be "junk".&lt;/P&gt;

&lt;P&gt;We have Splunk indexing logs from AD security and I have the below sedcmd configured:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;SEDCMD-shorternQPM = s/(.*QPM.*).*//g
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Post restarting the indexer service I couldn't see any noticeable difference in the output.&lt;/P&gt;

&lt;P&gt;Below is a snippet of the line where QPM exists:&lt;/P&gt;

&lt;P&gt;QPM=    &lt;OBJECT&gt;&lt;PARAM /&gt; &lt;PARAM /&gt; &lt;PARAM /&gt; &lt;PARAM /&gt; &lt;PARAM /&gt; &lt;PARAM /&gt; &lt;PARAM /&gt; &lt;PARAM /&gt; &lt;PARAM /&gt;   &lt;/OBJECT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 06:55:20 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-sedcmd-to-truncate-QPM/m-p/473876#M81374</guid>
      <dc:creator>eoc</dc:creator>
      <dc:date>2019-09-09T06:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: Using sedcmd to truncate QPM=</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-sedcmd-to-truncate-QPM/m-p/473877#M81375</link>
      <description>&lt;P&gt;You didn't give us much to work with.&lt;BR /&gt;&lt;BR /&gt;
The SEDCMD string is expecting a single character before "QPM", but the sample data has no such character.  That's one possible explanation for the failure.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 12:10:35 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-sedcmd-to-truncate-QPM/m-p/473877#M81375</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-09-09T12:10:35Z</dc:date>
    </item>
    <item>
      <title>Re: Using sedcmd to truncate QPM=</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-sedcmd-to-truncate-QPM/m-p/473878#M81376</link>
      <description>&lt;P&gt;Are you looking to truncate part of your raw data or just drop the whole event itself (no indexing)? If it's the latter, I would suggest reading/implementing this:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.3.1/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues"&gt;https://docs.splunk.com/Documentation/Splunk/7.3.1/Forwarding/Routeandfilterdatad#Filter_event_data_and_send_to_queues&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Your sample data and configuration entries will get truncated if you do not format them using "100010" button on top of the text editor in this page (or select and press Ctrl+K).&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 13:39:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-sedcmd-to-truncate-QPM/m-p/473878#M81376</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2019-09-09T13:39:42Z</dc:date>
    </item>
    <item>
      <title>Re: Using sedcmd to truncate QPM=</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-sedcmd-to-truncate-QPM/m-p/473879#M81377</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;

&lt;P&gt;Apologies, appears I hit a character limit.&lt;/P&gt;

&lt;P&gt;We need most of the log file and need to omit a small component of it.&lt;/P&gt;

&lt;P&gt;An example of a line we are attempting to clean can be seen below:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;QPM=&amp;lt;root&amp;gt; &amp;lt;QPM id="the-one"&amp;gt; &amp;lt;public&amp;gt; &amp;lt;Options&amp;gt; &amp;lt;param name="sprPrmLockCount" value="2" /&amp;gt; &amp;lt;param name="sprPrmLockTimestamp" value="11.06.2016 20:36:31" /&amp;gt; &amp;lt;param name="sprPrmLocked" value="no" /&amp;gt; &amp;lt;param name="Layout" value="M|M|M|M|M" /&amp;gt; &amp;lt;param name="sprAnswersHashed" value="no" /&amp;gt; &amp;lt;param name="sprForceEnrollStartDate" /&amp;gt; &amp;lt;param name="sprInvalidQAProfile" value="no" /&amp;gt; &amp;lt;param name="sprLID" value="en" /&amp;gt; &amp;lt;param name="sprShortestAnswerSize" value="5" /&amp;gt; &amp;lt;/Options&amp;gt; &amp;lt;/public&amp;gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Any help is much appreciated&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2019 23:38:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-sedcmd-to-truncate-QPM/m-p/473879#M81377</guid>
      <dc:creator>eoc</dc:creator>
      <dc:date>2019-09-09T23:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Using sedcmd to truncate QPM=</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-sedcmd-to-truncate-QPM/m-p/473880#M81378</link>
      <description>&lt;P&gt;What part do you need to omit?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2019 12:59:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-sedcmd-to-truncate-QPM/m-p/473880#M81378</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-09-10T12:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: Using sedcmd to truncate QPM=</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-sedcmd-to-truncate-QPM/m-p/473881#M81379</link>
      <description>&lt;P&gt;All of it from QPM to the end of the line&lt;/P&gt;</description>
      <pubDate>Mon, 16 Sep 2019 04:31:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-sedcmd-to-truncate-QPM/m-p/473881#M81379</guid>
      <dc:creator>eoc</dc:creator>
      <dc:date>2019-09-16T04:31:02Z</dc:date>
    </item>
    <item>
      <title>Re: Using sedcmd to truncate QPM=</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Using-sedcmd-to-truncate-QPM/m-p/473882#M81380</link>
      <description>&lt;P&gt;You don't say which "QPM", but &lt;CODE&gt;(QPM.*)&lt;/CODE&gt; should match everything from the first one.&lt;/P&gt;</description>
      <pubDate>Tue, 17 Sep 2019 12:55:15 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Using-sedcmd-to-truncate-QPM/m-p/473882#M81380</guid>
      <dc:creator>richgalloway</dc:creator>
      <dc:date>2019-09-17T12:55:15Z</dc:date>
    </item>
  </channel>
</rss>

