<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Nullqueue filtering in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Nullqueue-filtering/m-p/539516#M90381</link>
    <description>Is it totally impossible idea to have two almost identical serverclasses one for each?</description>
    <pubDate>Thu, 11 Feb 2021 16:22:53 GMT</pubDate>
    <dc:creator>isoutamo</dc:creator>
    <dc:date>2021-02-11T16:22:53Z</dc:date>
    <item>
      <title>Nullqueue filtering</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Nullqueue-filtering/m-p/538400#M90240</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;Grateful for assistance on this one.&lt;/P&gt;&lt;P&gt;We have several areas where servers are HA pairs and write to a server specific log.&amp;nbsp; However, because they are an HA pair, their own log and the equivalent log on the paired server is visible via a shared drive.&lt;/P&gt;&lt;P&gt;Thus,&amp;nbsp; server 'A' produces 'serverlogA' but can also see 'serverlogB'.&amp;nbsp; Server 'B' produces 'serverlogB' and can also see 'serverlogA'.&lt;/P&gt;&lt;P&gt;Because both servers are in the same Server Class, we end up with duplicated events from both server logs.&lt;/P&gt;&lt;P&gt;We cannot only ingest from one server because they also have unique log files and a failure on the ingesting server would require manual intervention to move to the paired server.&lt;/P&gt;&lt;P&gt;I have tried to nullqueue the events as shown below, but not had any success.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know your thoughts on how to work around this issue.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;props.conf&lt;/P&gt;&lt;P&gt;[source::/apps/lvservices/mnt/logs/abc/whyluaap182_ContractEnquiry.log]&lt;BR /&gt;TRANSFORMS-nullq_cms_uaap181 = nullq_uaap181&lt;BR /&gt;[source::/apps/lvservices/mnt/logs/abc/whyluaap181_ContractEnquiry.log]&lt;BR /&gt;TRANSFORMS-nullq_cms_uaap182 = nullq_uaap182&lt;/P&gt;&lt;P&gt;transforms.conf&lt;/P&gt;&lt;P&gt;[nullq_uaap181]&lt;BR /&gt;SOURCE_KEY = MetaData:Host&lt;BR /&gt;REGEX = whyluaap181&lt;BR /&gt;DEST_KEY = queue&lt;BR /&gt;FORMAT = nullQueue&lt;/P&gt;&lt;P&gt;[nullq_uaap182]&lt;BR /&gt;SOURCE_KEY = MetaData:Host&lt;BR /&gt;REGEX = whyluaap182&lt;BR /&gt;DEST_KEY = queue&lt;BR /&gt;FORMAT = nullQueue&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 10:06:02 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Nullqueue-filtering/m-p/538400#M90240</guid>
      <dc:creator>timrich66</dc:creator>
      <dc:date>2021-02-03T10:06:02Z</dc:date>
    </item>
    <item>
      <title>Re: Nullqueue filtering</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Nullqueue-filtering/m-p/538511#M90244</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/77822"&gt;@timrich66&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;These conf files should be on Indexers. Could you please confirm?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Feb 2021 19:41:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Nullqueue-filtering/m-p/538511#M90244</guid>
      <dc:creator>scelikok</dc:creator>
      <dc:date>2021-02-03T19:41:55Z</dc:date>
    </item>
    <item>
      <title>Re: Nullqueue filtering</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Nullqueue-filtering/m-p/539512#M90379</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/206061"&gt;@scelikok&lt;/a&gt;&amp;nbsp;, yes, the code is deployed from our Cluster Master (/opt/splunk/etc/master-apps/_cluster/local) to indexers (/opt/splunk/etc/slave-apps/_cluster/local).&amp;nbsp; It is also present on HF in /opt/splunk/etc/system/local).&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 16:06:38 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Nullqueue-filtering/m-p/539512#M90379</guid>
      <dc:creator>timrich66</dc:creator>
      <dc:date>2021-02-11T16:06:38Z</dc:date>
    </item>
    <item>
      <title>Re: Nullqueue filtering</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Nullqueue-filtering/m-p/539516#M90381</link>
      <description>Is it totally impossible idea to have two almost identical serverclasses one for each?</description>
      <pubDate>Thu, 11 Feb 2021 16:22:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Nullqueue-filtering/m-p/539516#M90381</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-02-11T16:22:53Z</dc:date>
    </item>
    <item>
      <title>Re: Nullqueue filtering</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Nullqueue-filtering/m-p/539527#M90382</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/214410"&gt;@isoutamo&lt;/a&gt;&amp;nbsp; Can you explain your thinking?&amp;nbsp; It is unlikely, but may be possible.&amp;nbsp; I don't understand why the nullqueue option isn't working though.&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 16:58:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Nullqueue-filtering/m-p/539527#M90382</guid>
      <dc:creator>timrich66</dc:creator>
      <dc:date>2021-02-11T16:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: Nullqueue filtering</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Nullqueue-filtering/m-p/539535#M90385</link>
      <description>&lt;P&gt;Now you have one serverclass where you have defined all those files: common, nodeA and nodeB if I understood right. As your log files contains name of nodeA or nodeB you could remove those from common serverclass and create separate classes for those which are installed only to corresponding node. All common files could be in common serverclass which will installed to both. Then there is no need for that nullQfiltering.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 11 Feb 2021 17:20:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Nullqueue-filtering/m-p/539535#M90385</guid>
      <dc:creator>isoutamo</dc:creator>
      <dc:date>2021-02-11T17:20:29Z</dc:date>
    </item>
  </channel>
</rss>

