<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: filtering content on index in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/filtering-content-on-index/m-p/49106#M9331</link>
    <description>&lt;P&gt;If the content will always follow a known pattern, you can use &lt;A href="http://www.splunk.com/base/Documentation/4.1.5/Admin/Anonymizedatawithsed" rel="nofollow"&gt;SEDCMD&lt;/A&gt; to filter out the text you don't want. Set the second part of the expression to be empty, e.g.: &lt;CODE&gt;SEDCMD-abc = s/StringToThrowAway//&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;Another possibility (at the event level) would be to create an entry in &lt;CODE&gt;transforms.conf&lt;/CODE&gt; matching the information you want suppressed, and route it to a null queue. See &lt;A href="http://www.splunk.com/base/Documentation/4.1.5/Admin/Routeandfilterdata#Discard_specific_events_and_keep_the_rest" rel="nofollow"&gt;here&lt;/A&gt; for an example.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Sep 2010 00:38:27 GMT</pubDate>
    <dc:creator>southeringtonp</dc:creator>
    <dc:date>2010-09-14T00:38:27Z</dc:date>
    <item>
      <title>filtering content on index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/filtering-content-on-index/m-p/49105#M9330</link>
      <description>&lt;P&gt;At a high level... how would one filter  the &lt;STRONG&gt;content&lt;/STRONG&gt; itself being indexed.&lt;/P&gt;

&lt;P&gt;Example: i was indexing ..say.. xml docs and wanted to &lt;STRONG&gt;exclude&lt;/STRONG&gt; the contents in a pair of xml tags.&lt;/P&gt;</description>
      <pubDate>Mon, 13 Sep 2010 23:30:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/filtering-content-on-index/m-p/49105#M9330</guid>
      <dc:creator>hiddenkirby</dc:creator>
      <dc:date>2010-09-13T23:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: filtering content on index</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/filtering-content-on-index/m-p/49106#M9331</link>
      <description>&lt;P&gt;If the content will always follow a known pattern, you can use &lt;A href="http://www.splunk.com/base/Documentation/4.1.5/Admin/Anonymizedatawithsed" rel="nofollow"&gt;SEDCMD&lt;/A&gt; to filter out the text you don't want. Set the second part of the expression to be empty, e.g.: &lt;CODE&gt;SEDCMD-abc = s/StringToThrowAway//&lt;/CODE&gt;.&lt;/P&gt;

&lt;P&gt;Another possibility (at the event level) would be to create an entry in &lt;CODE&gt;transforms.conf&lt;/CODE&gt; matching the information you want suppressed, and route it to a null queue. See &lt;A href="http://www.splunk.com/base/Documentation/4.1.5/Admin/Routeandfilterdata#Discard_specific_events_and_keep_the_rest" rel="nofollow"&gt;here&lt;/A&gt; for an example.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Sep 2010 00:38:27 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/filtering-content-on-index/m-p/49106#M9331</guid>
      <dc:creator>southeringtonp</dc:creator>
      <dc:date>2010-09-14T00:38:27Z</dc:date>
    </item>
  </channel>
</rss>

