<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Not Able to send data to Null Queue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Not-Able-to-send-data-to-Null-Queue/m-p/496242#M84656</link>
    <description>&lt;P&gt;Based on my PA logs, regex of USERID,login would match the logs you want, however YMMV as I cannot see what logs you've got coming in to Splunk.&lt;/P&gt;</description>
    <pubDate>Thu, 06 Feb 2020 01:11:38 GMT</pubDate>
    <dc:creator>Wallace44</dc:creator>
    <dc:date>2020-02-06T01:11:38Z</dc:date>
    <item>
      <title>Not Able to send data to Null Queue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-Able-to-send-data-to-Null-Queue/m-p/496240#M84654</link>
      <description>&lt;P&gt;Hi &lt;BR /&gt;
How to edit props.conf or blacklist the sub sourcetype &lt;/P&gt;

&lt;P&gt;Have integrated PALO ALTO logs to Splunk it is fetching 3 sourcetypes. The pan:log sourcetyoe having pan:userid as sub sourcetype, it's generating alot of events so I want to discard them. &lt;BR /&gt;
Tried with the Null Queue but the problem is for 1-minute window the userid is not coming whereas for 5-minute window it is coming.&lt;/P&gt;

&lt;P&gt;props.conf:&lt;BR /&gt;
[source::udp:514]&lt;BR /&gt;
TRANSFORMS-null_syslogs=pa_useridnull&lt;/P&gt;

&lt;P&gt;transforms:&lt;BR /&gt;
[pa_useridnull]&lt;BR /&gt;
REGEX = type=USERID&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = nullQueue&lt;/P&gt;</description>
      <pubDate>Wed, 30 Sep 2020 03:55:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-Able-to-send-data-to-Null-Queue/m-p/496240#M84654</guid>
      <dc:creator>istutig</dc:creator>
      <dc:date>2020-09-30T03:55:30Z</dc:date>
    </item>
    <item>
      <title>Re: Not Able to send data to Null Queue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-Able-to-send-data-to-Null-Queue/m-p/496241#M84655</link>
      <description>&lt;P&gt;I don't believe you can use type=USERID because that is a post index key pair that's generated. That regex won't match the raw logs.&lt;/P&gt;

&lt;P&gt;I'd suggest exporting a chunk of your logs, and then going to a regex builder site and modifying your regex to match. Most regex builder sites have a tool where you can paste data and it will highlight what your regex matches. regexr.com is a site that you might find handy.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 01:03:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-Able-to-send-data-to-Null-Queue/m-p/496241#M84655</guid>
      <dc:creator>Wallace44</dc:creator>
      <dc:date>2020-02-06T01:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: Not Able to send data to Null Queue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-Able-to-send-data-to-Null-Queue/m-p/496242#M84656</link>
      <description>&lt;P&gt;Based on my PA logs, regex of USERID,login would match the logs you want, however YMMV as I cannot see what logs you've got coming in to Splunk.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Feb 2020 01:11:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-Able-to-send-data-to-Null-Queue/m-p/496242#M84656</guid>
      <dc:creator>Wallace44</dc:creator>
      <dc:date>2020-02-06T01:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: Not Able to send data to Null Queue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Not-Able-to-send-data-to-Null-Queue/m-p/518921#M87743</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having same problem. Can you please provide solution if issue is resolved?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2020 16:57:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Not-Able-to-send-data-to-Null-Queue/m-p/518921#M87743</guid>
      <dc:creator>rc15</dc:creator>
      <dc:date>2020-09-10T16:57:09Z</dc:date>
    </item>
  </channel>
</rss>

