<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Filtering out the message and body fields from wineventlog in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-out-the-message-and-body-fields-from-wineventlog/m-p/555207#M91977</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207926"&gt;@anandhalagaras1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have replied a solution similar to your case, you can check the same here -&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Windows-Filtering-Forwarded-Events-based-on-LogName/m-p/553711#M91798" target="_blank"&gt;Solved: Windows - Filtering Forwarded Events based on LogN... - Splunk Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Let me know how you go.&amp;nbsp;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if it helps!&lt;/P&gt;</description>
    <pubDate>Thu, 10 Jun 2021 01:36:39 GMT</pubDate>
    <dc:creator>venkatasri</dc:creator>
    <dc:date>2021-06-10T01:36:39Z</dc:date>
    <item>
      <title>Filtering out the message and body fields from wineventlog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-out-the-message-and-body-fields-from-wineventlog/m-p/554208#M91844</link>
      <description>&lt;P&gt;Hi Team,&lt;/P&gt;&lt;P&gt;We are already ingesting wineventlog in splunk. So we are currently working towards the license usage reduction for wineventlog and we have the&amp;nbsp;Splunk_TA_windows - 8.0.0 version installed and all the fields are getting extracted as desired. So now I can see there are two fields getting extracted i.e. One of which is the "Message" and another the field is "body"&lt;/P&gt;&lt;P&gt;So both of them are having the same or identical data so if we filter out both the fields or any of the field then i believe we could save few amount of licenses.&lt;/P&gt;&lt;P&gt;So I have tried as below in my inputs.conf stanza of my wineventlog inputs but still either the Message or body field is not getting filtered out.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[WinEventLog://Security]&lt;BR /&gt;disabled = 0&lt;BR /&gt;suppress_text = 1&lt;/P&gt;&lt;P&gt;[WinEventLog://System]&lt;BR /&gt;disabled = 0&lt;BR /&gt;suppress_text = 1&lt;/P&gt;&lt;P&gt;[WinEventLog://Application]&lt;BR /&gt;disabled = 0&lt;BR /&gt;suppress_text = 1&lt;/P&gt;&lt;P&gt;If it is possible i want to filter out both the fields "body" and "Message" or atleast the body field alone so that we would be able to save some licensing.&lt;/P&gt;&lt;P&gt;So kindly help out with the inputs for the same.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Jun 2021 07:06:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-out-the-message-and-body-fields-from-wineventlog/m-p/554208#M91844</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2021-06-03T07:06:26Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering out the message and body fields from wineventlog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-out-the-message-and-body-fields-from-wineventlog/m-p/554637#M91905</link>
      <description>&lt;P&gt;Can anyone kindly help on my request please.&lt;/P&gt;</description>
      <pubDate>Mon, 07 Jun 2021 06:48:10 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-out-the-message-and-body-fields-from-wineventlog/m-p/554637#M91905</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2021-06-07T06:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering out the message and body fields from wineventlog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-out-the-message-and-body-fields-from-wineventlog/m-p/555207#M91977</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207926"&gt;@anandhalagaras1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have replied a solution similar to your case, you can check the same here -&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Windows-Filtering-Forwarded-Events-based-on-LogName/m-p/553711#M91798" target="_blank"&gt;Solved: Windows - Filtering Forwarded Events based on LogN... - Splunk Community&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Let me know how you go.&amp;nbsp;&lt;/P&gt;&lt;P&gt;--&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if it helps!&lt;/P&gt;</description>
      <pubDate>Thu, 10 Jun 2021 01:36:39 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-out-the-message-and-body-fields-from-wineventlog/m-p/555207#M91977</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-06-10T01:36:39Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering out the message and body fields from wineventlog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-out-the-message-and-body-fields-from-wineventlog/m-p/555620#M92011</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163730"&gt;@venkatasri&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;Thank you for your response. But its not filtering out for particular event id but instead I want to completely remove the field before getting ingested into Splunk.&lt;/P&gt;&lt;P&gt;Currently I can see two fields in our Splunk console one is "body" and another one is "Message". So when i checked the information both seems to be the same.&lt;/P&gt;&lt;P&gt;Example of an event:&lt;/P&gt;&lt;P&gt;body -- &amp;gt;An account was logged off. Subject: Security ID: x-xx-xx-xx-xxxxxxxxx-xxxxx-xxxxxxx-xxxxx Account Name: ABCDEFGH$ Account Domain: XX Logon ID: 1w23456ewera Logon Type: 3&lt;/P&gt;&lt;P&gt;Message --&amp;gt;An account was logged off. Subject: Security ID: x-xx-xx-xx-xxxxxxxxx-xxxxx-xxxxxxx-xxxxx Account Name: ABCDEFGH$ Account Domain: XX Logon ID: 1w23456ewera Logon Type: 3&lt;/P&gt;&lt;P&gt;So similarly there would be another type of "body" field and the same would be in "Message" field .&lt;/P&gt;&lt;P&gt;So&amp;nbsp; if i remove the "body" field then we can remove the duplicate data which in turn helps to save license.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So kindly help to provide with the stanza so that i can test it out in inputs.conf&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 06:15:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-out-the-message-and-body-fields-from-wineventlog/m-p/555620#M92011</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2021-06-14T06:15:45Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering out the message and body fields from wineventlog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-out-the-message-and-body-fields-from-wineventlog/m-p/555628#M92013</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207926"&gt;@anandhalagaras1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If the both fields belongs to same event they can not be dropped to save license. There is no reference in splunk docs, alternatively you can raise a support case.&lt;/P&gt;&lt;P&gt;----&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if it helps!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Jun 2021 07:30:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-out-the-message-and-body-fields-from-wineventlog/m-p/555628#M92013</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-06-14T07:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering out the message and body fields from wineventlog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-out-the-message-and-body-fields-from-wineventlog/m-p/555703#M92027</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207926"&gt;@anandhalagaras1&lt;/a&gt;&amp;nbsp;Alternative solution is to break the event into two different events 1 body, 1 message. If you are fully confident both having same information then you can send either body/message into nullQueue based on key-word.&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if it helps!&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 00:35:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-out-the-message-and-body-fields-from-wineventlog/m-p/555703#M92027</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-06-15T00:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering out the message and body fields from wineventlog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-out-the-message-and-body-fields-from-wineventlog/m-p/555720#M92035</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/163730"&gt;@venkatasri&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually i want to send the "body" field to nullQueue. So How can I send to nullQueue do we need to write props and transforms for the same. Or should I make them stop by updating in inputs.conf kindly help me with the stanza if possible.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 05:59:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-out-the-message-and-body-fields-from-wineventlog/m-p/555720#M92035</guid>
      <dc:creator>anandhalagaras1</dc:creator>
      <dc:date>2021-06-15T05:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering out the message and body fields from wineventlog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-out-the-message-and-body-fields-from-wineventlog/m-p/555722#M92037</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207926"&gt;@anandhalagaras1&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;If your body, message are belongs to same event which means technically that's _raw field. When you send to nullQueue entire event will be lost. Yes props and transforms conf are the way forward.&lt;/P&gt;&lt;P&gt;refer -&amp;nbsp;&lt;A href="https://docs.splunk.com/Documentation/Splunk/8.2.0/Admin/Transformsconf#transforms.conf.example" target="_blank"&gt;transforms.conf - Splunk Documentation&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 06:06:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-out-the-message-and-body-fields-from-wineventlog/m-p/555722#M92037</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-06-15T06:06:28Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering out the message and body fields from wineventlog</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-out-the-message-and-body-fields-from-wineventlog/m-p/555725#M92038</link>
      <description>&lt;P&gt;&lt;a href="https://community.splunk.com/t5/user/viewprofilepage/user-id/207926"&gt;@anandhalagaras1&lt;/a&gt;&amp;nbsp;if you still wish to proceed refer this link -&amp;nbsp;&lt;A href="https://community.splunk.com/t5/Getting-Data-In/Filtering-events-using-NullQueue/m-p/66392" target="_blank"&gt;Solved: Filtering events using NullQueue - Splunk Community&lt;/A&gt;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;# props.cong setting
[your_sourcetype]
TRANSFORMS-delete = sendtonullqueue

# transforms.conf settings
[sendtonullqueue]
REGEX = &amp;lt;this_should_match_your_body_uniquely&amp;gt;
DEST_KEY=queue
FORMAT=nullQueue

#Both these settings shall be deployed to indexer/HF &lt;/LI-CODE&gt;&lt;P&gt;----&lt;/P&gt;&lt;P&gt;An upvote would be appreciated if it helps!&lt;/P&gt;</description>
      <pubDate>Tue, 15 Jun 2021 06:42:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-out-the-message-and-body-fields-from-wineventlog/m-p/555725#M92038</guid>
      <dc:creator>venkatasri</dc:creator>
      <dc:date>2021-06-15T06:42:13Z</dc:date>
    </item>
  </channel>
</rss>

