<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Yet Another Problem Sending Events to the nullQueue in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Yet-Another-Problem-Sending-Events-to-the-nullQueue/m-p/13495#M88280</link>
    <description>&lt;P&gt;We are using "heavy" forwarders, but I have the following config on both the forwarder and the indexer but the events are not being dropped for some reason.&lt;/P&gt;

&lt;P&gt;A typical event that we are trying to drop looks like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;=INFO REPORT==== 14-May-2010::00:00:54 
=== closing TCP connection &amp;lt;0.17671.5&amp;gt; from 10.1.1.1:12345
sourcetype=rabbit
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[rabbit*]
TRANSFORMS-rabbit=rabbit
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[rabbit]
REGEX=(?m)INFO REPORT
DEST_KEY=queue
FORMAT=nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The sourcetype is set in inputs.conf, I have removed all references to rabbit in the learned app&lt;/P&gt;</description>
    <pubDate>Fri, 14 May 2010 07:12:13 GMT</pubDate>
    <dc:creator>oreoshake</dc:creator>
    <dc:date>2010-05-14T07:12:13Z</dc:date>
    <item>
      <title>Yet Another Problem Sending Events to the nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Yet-Another-Problem-Sending-Events-to-the-nullQueue/m-p/13495#M88280</link>
      <description>&lt;P&gt;We are using "heavy" forwarders, but I have the following config on both the forwarder and the indexer but the events are not being dropped for some reason.&lt;/P&gt;

&lt;P&gt;A typical event that we are trying to drop looks like this:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;=INFO REPORT==== 14-May-2010::00:00:54 
=== closing TCP connection &amp;lt;0.17671.5&amp;gt; from 10.1.1.1:12345
sourcetype=rabbit
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[rabbit*]
TRANSFORMS-rabbit=rabbit
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[rabbit]
REGEX=(?m)INFO REPORT
DEST_KEY=queue
FORMAT=nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;The sourcetype is set in inputs.conf, I have removed all references to rabbit in the learned app&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2010 07:12:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Yet-Another-Problem-Sending-Events-to-the-nullQueue/m-p/13495#M88280</guid>
      <dc:creator>oreoshake</dc:creator>
      <dc:date>2010-05-14T07:12:13Z</dc:date>
    </item>
    <item>
      <title>Re: Yet Another Problem Sending Events to the nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Yet-Another-Problem-Sending-Events-to-the-nullQueue/m-p/13496#M88281</link>
      <description>&lt;P&gt;Do the "rabbit" results returned in the UI match any in $SPLUNK_HOME/etc/apps/learned/local/props.conf&lt;BR /&gt;
Occasionally splunk will learn the wrong sourcetype, you can actually delete entries out of the learned props.conf if it does not match the props.conf entries you want.&lt;/P&gt;

&lt;P&gt;The sourcetype-too_small entries usually mean the amount of data splunk was trying to learn/create props from was too small in the file, source etc...&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2010 04:44:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Yet-Another-Problem-Sending-Events-to-the-nullQueue/m-p/13496#M88281</guid>
      <dc:creator>Chris_R_</dc:creator>
      <dc:date>2010-05-19T04:44:06Z</dc:date>
    </item>
    <item>
      <title>Re: Yet Another Problem Sending Events to the nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Yet-Another-Problem-Sending-Events-to-the-nullQueue/m-p/13497#M88282</link>
      <description>&lt;P&gt;I deleted the entries in etc/app/learned/local/props.conf.  Also, the sourcetype originally wasn't set in inputs so it's possible that the learned types were causing my transform to be skipped.  I fixed this so the sourcetype is set in inputs.conf but my transform still isn't being applied&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2010 05:17:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Yet-Another-Problem-Sending-Events-to-the-nullQueue/m-p/13497#M88282</guid>
      <dc:creator>oreoshake</dc:creator>
      <dc:date>2010-05-19T05:17:04Z</dc:date>
    </item>
    <item>
      <title>Re: Yet Another Problem Sending Events to the nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Yet-Another-Problem-Sending-Events-to-the-nullQueue/m-p/13498#M88283</link>
      <description>&lt;P&gt;No sourcetype was set in inputs.conf, causing it to be set by props.conf in the learned app, thus ignoring my second props entry that was less specific.  After setting the sourcetype in inputs.conf and deleting the entries in the learned app, I had to remove the trailing * to get the transform to be applied.&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2010 05:56:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Yet-Another-Problem-Sending-Events-to-the-nullQueue/m-p/13498#M88283</guid>
      <dc:creator>oreoshake</dc:creator>
      <dc:date>2010-05-19T05:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Yet Another Problem Sending Events to the nullQueue</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Yet-Another-Problem-Sending-Events-to-the-nullQueue/m-p/13499#M88284</link>
      <description>&lt;P&gt;Ok great, yeah setting the sourcetype in inputs.conf is usually the way to go.&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2010 06:17:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Yet-Another-Problem-Sending-Events-to-the-nullQueue/m-p/13499#M88284</guid>
      <dc:creator>Chris_R_</dc:creator>
      <dc:date>2010-05-19T06:17:05Z</dc:date>
    </item>
  </channel>
</rss>

