<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Heavy Forwarded Filtering Hosts in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarded-Filtering-Hosts/m-p/536353#M89911</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I've ready a ton of forums posts regarding this but I still cannot get it to work so I'm hoping someone could point out what I'm doing wrong.&lt;/P&gt;&lt;P&gt;The scenario I have is there are multiple hosts with the Splunk agent installed on it and we're currently logging that data to our Splunk indexers + a syslog server. For a short period of time, I want to send a subset of logs only to syslog but I can't seem to get that to work.&lt;/P&gt;&lt;P&gt;Below is my current config on my heavy forwarders. I expect this to send all hosts with server* to Splunk and syslog but only endpoint* to syslog.&lt;/P&gt;&lt;P&gt;Right now no matter what I do, everything still goes to Splunk. I even fully commented out the&amp;nbsp;routeSubset section and "splunk reload deploy-server" and I still got those logs in Splunk&lt;/P&gt;&lt;P&gt;Any thoughts would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;props.conf&lt;/STRONG&gt;&lt;BR /&gt;[source::WinEventLog:Security]&lt;BR /&gt;TRUNCATE = 0&lt;BR /&gt;SEDCMD-win = s/(?mis)(Token\sElevation\sType\sindicates|This\sevent\sis\sgenerated).*$//g&lt;BR /&gt;TRANSFORMS-routing = routeSubset, routeSubset2&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;transforms.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[routeSubset]&lt;BR /&gt;SOURCE_KEY=MetaData:Host&lt;BR /&gt;REGEX=(?i)^server[0-9][0-9].*&lt;BR /&gt;DEST_KEY=_TCP_ROUTING&lt;BR /&gt;FORMAT=splunkssl&lt;/P&gt;&lt;P&gt;[routeSubset2]&lt;BR /&gt;SOURCE_KEY=MetaData:Host&lt;BR /&gt;REGEX=(?i)(.*endpoint[0-9][0-9].*|^server[0-9][0-9].*)&lt;BR /&gt;DEST_KEY=_SYSLOG_ROUTING&lt;BR /&gt;FORMAT=syslog_server&lt;/P&gt;</description>
    <pubDate>Tue, 19 Jan 2021 17:23:58 GMT</pubDate>
    <dc:creator>ericl42</dc:creator>
    <dc:date>2021-01-19T17:23:58Z</dc:date>
    <item>
      <title>Heavy Forwarded Filtering Hosts</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarded-Filtering-Hosts/m-p/536353#M89911</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I've ready a ton of forums posts regarding this but I still cannot get it to work so I'm hoping someone could point out what I'm doing wrong.&lt;/P&gt;&lt;P&gt;The scenario I have is there are multiple hosts with the Splunk agent installed on it and we're currently logging that data to our Splunk indexers + a syslog server. For a short period of time, I want to send a subset of logs only to syslog but I can't seem to get that to work.&lt;/P&gt;&lt;P&gt;Below is my current config on my heavy forwarders. I expect this to send all hosts with server* to Splunk and syslog but only endpoint* to syslog.&lt;/P&gt;&lt;P&gt;Right now no matter what I do, everything still goes to Splunk. I even fully commented out the&amp;nbsp;routeSubset section and "splunk reload deploy-server" and I still got those logs in Splunk&lt;/P&gt;&lt;P&gt;Any thoughts would be greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;props.conf&lt;/STRONG&gt;&lt;BR /&gt;[source::WinEventLog:Security]&lt;BR /&gt;TRUNCATE = 0&lt;BR /&gt;SEDCMD-win = s/(?mis)(Token\sElevation\sType\sindicates|This\sevent\sis\sgenerated).*$//g&lt;BR /&gt;TRANSFORMS-routing = routeSubset, routeSubset2&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;transforms.conf&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;[routeSubset]&lt;BR /&gt;SOURCE_KEY=MetaData:Host&lt;BR /&gt;REGEX=(?i)^server[0-9][0-9].*&lt;BR /&gt;DEST_KEY=_TCP_ROUTING&lt;BR /&gt;FORMAT=splunkssl&lt;/P&gt;&lt;P&gt;[routeSubset2]&lt;BR /&gt;SOURCE_KEY=MetaData:Host&lt;BR /&gt;REGEX=(?i)(.*endpoint[0-9][0-9].*|^server[0-9][0-9].*)&lt;BR /&gt;DEST_KEY=_SYSLOG_ROUTING&lt;BR /&gt;FORMAT=syslog_server&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jan 2021 17:23:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Heavy-Forwarded-Filtering-Hosts/m-p/536353#M89911</guid>
      <dc:creator>ericl42</dc:creator>
      <dc:date>2021-01-19T17:23:58Z</dc:date>
    </item>
  </channel>
</rss>

