<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Need help in extracting  network events before indexing in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-in-extracting-network-events-before-indexing/m-p/533452#M89598</link>
    <description>&lt;P&gt;Is it possible to use props and transforms in UF?&lt;/P&gt;</description>
    <pubDate>Thu, 17 Dec 2020 13:55:38 GMT</pubDate>
    <dc:creator>sivaranjiniG</dc:creator>
    <dc:date>2020-12-17T13:55:38Z</dc:date>
    <item>
      <title>Need help in extracting  network events before indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-in-extracting-network-events-before-indexing/m-p/533436#M89595</link>
      <description>&lt;P&gt;I have a file with full of logs from different sources. But i want to monitor only logs from a particular network device(cisco-ise). Please help me do it using props&lt;/P&gt;&lt;P&gt;here in the example wherever&amp;nbsp;&amp;lt;ise-hostname&amp;gt; those has to be monitored(means before going to indexer it should extract ise logs&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;Oct  6 03:44:01 &amp;lt;hostname&amp;gt; rsyslogd: [origin software="rsyslogd" swVersion="5.8.10" x-pid="1294" x-info="http://www.rsyslog.com"] rsyslogd was HUPed
Oct  6 03:44:02 &amp;lt;hostname&amp;gt; rhsmd: This system is registered to RHN Classic.
Oct  6 03:44:06 &amp;lt;ise-hostname&amp;gt; &amp;lt;hostname&amp;gt;: Dropping Primary discovery request from AP  - limit for maximum APs supported 30 reached
Oct  6 03:40:16 &amp;lt;ise-hostname&amp;gt; CISE_Failed_Attempts  1 0 2019-10-06 03:40:16.968 +05:30 NOTICE Failed-Attempt: RADIUS Accounting-Request dropped, ConfigVersionId=62, Device IP Address=&amp;lt;ip-address&amp;gt;, Device Port=&amp;lt;PORT&amp;gt;, DestinationIPAddress=&amp;lt;ip-address&amp;gt;, DestinationPort=&amp;lt;PORT&amp;gt;, Protocol=Radius, User-Name=ppp, Acct-Status-Type=Start, Acct-Session Id=sfaksdaksf, Event-Ti
mestamp=1569504083, AcsSessionID=&amp;lt;hostname&amp;gt;/asdasd, FailureReason=11007 Could not locate Network Device , Step=333, Step=55, Step=22, Step=11, #44
Oct  6 03:44:09 &amp;lt;hostname&amp;gt;: MOBILESTATION_NOT_FOUND: Could not find the mobile sadas in internal database
Oct  6 03:40:26 &amp;lt;ise-hostname&amp;gt; CISE_Failed_Attempts 1 0 2019-10-06 03:40:26.180 +05:30 NOTICE Failed-Attempt: RADIUS Accounting-Request dropped, ConfigVersionId=62, Device IP Address=&amp;lt;ip-address&amp;gt;, Device Port=&amp;lt;port&amp;gt;, DestinationIPAddress=&amp;lt;ip-address&amp;gt;, DestinationPort=&amp;lt;port&amp;gt;, Protocol=Radius, User-Name=wipro, Acct-Status-Type=Start, Acct-Session-Id=sdfsdfs, Event-Timestamp=1569504083, AcsSessionID=dfsdf, FailureReason=33 Could not locate Network Device , Step=343, Step=231, Step=55, Step=11, #44&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 13:10:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-help-in-extracting-network-events-before-indexing/m-p/533436#M89595</guid>
      <dc:creator>sivaranjiniG</dc:creator>
      <dc:date>2020-12-17T13:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in extracting  network events before indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-in-extracting-network-events-before-indexing/m-p/533442#M89596</link>
      <description>&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.1.1/Forwarding/Routeandfilterdatad#Keep_specific_events_and_discard_the_rest" target="_blank"&gt;https://docs.splunk.com/Documentation/Splunk/8.1.1/Forwarding/Routeandfilterdatad#Keep_specific_events_and_discard_the_rest&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;how about &lt;STRONG&gt;queue&lt;/STRONG&gt; and &lt;STRONG&gt;nullqueue&lt;/STRONG&gt;?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 13:31:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-help-in-extracting-network-events-before-indexing/m-p/533442#M89596</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-12-17T13:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in extracting  network events before indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-in-extracting-network-events-before-indexing/m-p/533452#M89598</link>
      <description>&lt;P&gt;Is it possible to use props and transforms in UF?&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 13:55:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-help-in-extracting-network-events-before-indexing/m-p/533452#M89598</guid>
      <dc:creator>sivaranjiniG</dc:creator>
      <dc:date>2020-12-17T13:55:38Z</dc:date>
    </item>
    <item>
      <title>Re: Need help in extracting  network events before indexing</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Need-help-in-extracting-network-events-before-indexing/m-p/533453#M89599</link>
      <description>&lt;P&gt;This is not possible at UF.&amp;nbsp;Please use indexer to do this.&lt;BR /&gt;This will not affect the license.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.splunk.com/t5/Installation/Filter-Indexing-to-Avoid-License-Issues/m-p/91903" target="_blank"&gt;https://community.splunk.com/t5/Installation/Filter-Indexing-to-Avoid-License-Issues/m-p/91903&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 13:59:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Need-help-in-extracting-network-events-before-indexing/m-p/533453#M89599</guid>
      <dc:creator>to4kawa</dc:creator>
      <dc:date>2020-12-17T13:59:29Z</dc:date>
    </item>
  </channel>
</rss>

