<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How I can index specific part of log ? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420419#M94442</link>
    <description>&lt;P&gt;That is if you are dumping the entire events; are you dumping "some events in the log" or "some data in each event"?  See my answer for &lt;CODE&gt;SEDCMD&lt;/CODE&gt; example for the latter.  In any case, the settings need to go on the HF or Indexers, not on the UF.&lt;/P&gt;</description>
    <pubDate>Thu, 05 Jul 2018 16:12:41 GMT</pubDate>
    <dc:creator>woodcock</dc:creator>
    <dc:date>2018-07-05T16:12:41Z</dc:date>
    <item>
      <title>How I can index specific part of log ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420414#M94437</link>
      <description>&lt;P&gt;Hello, I'm noob in this and I don't know still work with .conf files, I hope you can help me&lt;/P&gt;

&lt;P&gt;I have a universal forwarder that forward big log file. In the indexer, how can I index only specific part of log and the rest skip? I don't know still work  with .conf files&lt;/P&gt;

&lt;P&gt;Thank you in advance&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jul 2018 16:15:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420414#M94437</guid>
      <dc:creator>rjfv8205</dc:creator>
      <dc:date>2018-07-04T16:15:51Z</dc:date>
    </item>
    <item>
      <title>Re: How I can index specific part of log ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420415#M94438</link>
      <description>&lt;P&gt;Hi @rjfv8205 &lt;/P&gt;

&lt;P&gt;You can filter data in splunk. Start from here &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.1/Forwarding/Routeandfilterdatad"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.1/Forwarding/Routeandfilterdatad&lt;/A&gt; . If you need to filter a huge portion of the file, it might be useful to have a script to extract the log file entries you need to index and forward to splunk&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 00:54:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420415#M94438</guid>
      <dc:creator>renjith_nair</dc:creator>
      <dc:date>2018-07-05T00:54:05Z</dc:date>
    </item>
    <item>
      <title>Re: How I can index specific part of log ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420416#M94439</link>
      <description>&lt;P&gt;You use &lt;CODE&gt;SEDCMD&lt;/CODE&gt;; see this Q&amp;amp;A for an example:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;&lt;A href="https://answers.splunk.com/answers/668196/eliminate-unnecessary-values-when-indexing.html" target="test_blank"&gt;https://answers.splunk.com/answers/668196/eliminate-unnecessary-values-when-indexing.html&lt;/A&gt;
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Also @coccyx has an alpha/beta of a new tool that might help you.  Clint, what do you say?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 01:18:49 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420416#M94439</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-07-05T01:18:49Z</dc:date>
    </item>
    <item>
      <title>Re: How I can index specific part of log ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420417#M94440</link>
      <description>&lt;P&gt;Thanks @woodcock! This is possible with SEDCMD and works out of the box with Splunk, so certainly go down that route first. Helping transform data after the forwarder has picked it up off disk but before it gets written to indexer is one area we're looking to make better. Feel free to reach out to me &lt;A href="mailto:clint@diag.ai"&gt;clint@diag.ai&lt;/A&gt; if you find you need a better solution in this area!&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 03:06:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420417#M94440</guid>
      <dc:creator>coccyx</dc:creator>
      <dc:date>2018-07-05T03:06:55Z</dc:date>
    </item>
    <item>
      <title>Re: How I can index specific part of log ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420418#M94441</link>
      <description>&lt;P&gt;Thank you !! I'll do test, but i have a question about this:&lt;/P&gt;

&lt;P&gt;Following example in the topic &lt;STRONG&gt;"Filter event data and send to queues"&lt;/STRONG&gt;&lt;/P&gt;

&lt;P&gt;Edit props.conf and transforms.conf  in universal forwarder to send specific data?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 16:08:24 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420418#M94441</guid>
      <dc:creator>rjfv8205</dc:creator>
      <dc:date>2018-07-05T16:08:24Z</dc:date>
    </item>
    <item>
      <title>Re: How I can index specific part of log ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420419#M94442</link>
      <description>&lt;P&gt;That is if you are dumping the entire events; are you dumping "some events in the log" or "some data in each event"?  See my answer for &lt;CODE&gt;SEDCMD&lt;/CODE&gt; example for the latter.  In any case, the settings need to go on the HF or Indexers, not on the UF.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 16:12:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420419#M94442</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-07-05T16:12:41Z</dc:date>
    </item>
    <item>
      <title>Re: How I can index specific part of log ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420420#M94443</link>
      <description>&lt;P&gt;What does dumping mean? Sorry I'm from Chile and i try write english best possible jajaja.&lt;/P&gt;

&lt;P&gt;If the configuration is in indexer. How I write correctly in props.conf and transfrom.conf for that specific inputs (not all inputs) from UF indexer keep specific entries? &lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 16:24:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420420#M94443</guid>
      <dc:creator>rjfv8205</dc:creator>
      <dc:date>2018-07-05T16:24:18Z</dc:date>
    </item>
    <item>
      <title>Re: How I can index specific part of log ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420421#M94444</link>
      <description>&lt;P&gt;Hi again @woodcock I have tested this and results is not expected. &lt;/P&gt;

&lt;P&gt;For example I have this event in log:&lt;/P&gt;

&lt;P&gt;18-05-30;15:38:06.282 \hola.1,237      aaaaaa           bbb&lt;BR /&gt;
       ccccccc          ddd&lt;/P&gt;

&lt;P&gt;With configuration below index all events that cointain ddd in log&lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;P&gt;[tef]&lt;BR /&gt;
TRANSFORMS-set= setnull,setparsing&lt;/P&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;P&gt;[setnull]&lt;BR /&gt;
REGEX = .&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = nullQueue&lt;/P&gt;

&lt;P&gt;[setparsing]&lt;BR /&gt;
REGEX = ddd&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = indexQueue&lt;/P&gt;

&lt;P&gt;But I want only index ddd&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 19:29:45 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420421#M94444</guid>
      <dc:creator>rjfv8205</dc:creator>
      <dc:date>2018-07-05T19:29:45Z</dc:date>
    </item>
    <item>
      <title>Re: How I can index specific part of log ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420422#M94445</link>
      <description>&lt;P&gt;Considering an event like this in sourcetype &lt;CODE&gt;tef&lt;/CODE&gt;:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;18-05-30;15:38:06.282 \hola.1,237 aaaaaa bbb ccccccc ddd
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;To index only events that cointain &lt;CODE&gt;ddd&lt;/CODE&gt; put:&lt;/P&gt;

&lt;P&gt;In props.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[tef]
TRANSFORMS-set= setnull,setparsing
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;In transforms.conf:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[setnull]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue

[setparsing]
REGEX = ddd
DEST_KEY = queue
FORMAT = indexQueue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Deploy this to your HF and Indexers and restart all Splunk instances and only check events that are indexed after the restart.&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 20:29:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420422#M94445</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-07-05T20:29:37Z</dc:date>
    </item>
    <item>
      <title>Re: How I can index specific part of log ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420423#M94446</link>
      <description>&lt;P&gt;Yes, it work but I want index only "ddd" match,  no event complete. How can I do?&lt;/P&gt;</description>
      <pubDate>Thu, 05 Jul 2018 21:00:33 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420423#M94446</guid>
      <dc:creator>rjfv8205</dc:creator>
      <dc:date>2018-07-05T21:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: How I can index specific part of log ?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420424#M94447</link>
      <description>&lt;P&gt;OK, then you also need something like this (do try to write a better RegEx but this one will work) in your props.conf in the same section:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;SEDCMD-keep_only_ddd = s/^.*?\(ddd).*$/\1/
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Fri, 06 Jul 2018 00:08:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-I-can-index-specific-part-of-log/m-p/420424#M94447</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2018-07-06T00:08:04Z</dc:date>
    </item>
  </channel>
</rss>

