<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to configure in props/transforms.conf to remove the event data which does not contain any information in it? in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398304#M94564</link>
    <description>&lt;P&gt;thanks Somesoni2, let me try that.&lt;/P&gt;</description>
    <pubDate>Thu, 21 Jun 2018 15:38:13 GMT</pubDate>
    <dc:creator>Hemnaath</dc:creator>
    <dc:date>2018-06-21T15:38:13Z</dc:date>
    <item>
      <title>How to configure in props/transforms.conf to remove the event data which does not contain any information in it?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398293#M94553</link>
      <description>&lt;P&gt;Hi Splunk experts,&lt;/P&gt;

&lt;P&gt;Just want to know  how can I remove events which does not contain any information in it?&lt;BR /&gt;
Example&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5246iD8306ACA4616C21A/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;sample events which have information on them.&lt;/P&gt;

&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper" image-alt="alt text"&gt;&lt;img src="https://community.splunk.com/t5/image/serverpage/image-id/5247i7041820A403B7C6B/image-size/large?v=v2&amp;amp;px=999" role="button" title="alt text" alt="alt text" /&gt;&lt;/span&gt;&lt;/P&gt;

&lt;P&gt;I know that, we have to configure Route and Filter data in Props/transforms to achieve this but not sure about the Regex. &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Props.conf details:
[who]
TRANSFORMS-null= setnull

Transforms.conf details:
[setnull]
 REGEX = 
 DEST_KEY = queue
 FORMAT = nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Kindly guide me on this &lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2018 16:55:41 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398293#M94553</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2018-06-20T16:55:41Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure in props/transforms.conf to remove the event data which does not contain any information in it?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398294#M94554</link>
      <description>&lt;P&gt;The REGEX will depend upon how your event looks like when it has information. Could you provide some sample events which have information on them?&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2018 18:17:19 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398294#M94554</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-06-20T18:17:19Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure in props/transforms.conf to remove the event data which does not contain any information in it?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398295#M94555</link>
      <description>&lt;P&gt;If the Question contains the example data, then perhaps something like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;REGEX = ^USERNAME\s+LINE\s+HOSTNAME\s+TIME$
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 20 Jun 2018 19:08:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398295#M94555</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2018-06-20T19:08:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure in props/transforms.conf to remove the event data which does not contain any information in it?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398296#M94556</link>
      <description>&lt;P&gt;Hi Somesoni2,  thanks for your effort on this, we are monitoring wtmpx file from the unix machines using the Splunk Add-on for Unix.  Below are the sample events contains the information. &lt;/P&gt;

&lt;P&gt;Index=unix sourcetype=who host=* &lt;/P&gt;

&lt;P&gt;6/20/18&lt;BR /&gt;
3:06:05.000 PM&lt;BR /&gt;&lt;BR /&gt;
USERNAME        LINE        HOSTNAME                                  TIME&lt;BR /&gt;
DBB019        pts/1       w442xty1.XXXX.com                     Jun 19 18:40&lt;BR /&gt;
AMM007        pts/5       yb33gnn1.XXXX.com                     Jun 19 08:53&lt;BR /&gt;
host =  ttbmt02 source =    who sourcetype =    who&lt;BR /&gt;
6/20/18&lt;BR /&gt;
3:03:35.000 PM&lt;BR /&gt;&lt;BR /&gt;
USERNAME        LINE        HOSTNAME                                  TIME&lt;BR /&gt;
DBB019        pts/1       w442xty1.XXXX.com                     Jun 19 18:40&lt;BR /&gt;
AMM007        pts/5       yb33gnn1.XXXX.com                     Jun 19 08:53&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2018 19:31:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398296#M94556</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2018-06-20T19:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure in props/transforms.conf to remove the event data which does not contain any information in it?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398297#M94557</link>
      <description>&lt;P&gt;Hi cpetterborg, thanks for your effort on this,  I had added the sample events containing the data, so can I use the above regex to remove events which does not contain any information in it.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2018 19:33:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398297#M94557</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2018-06-20T19:33:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure in props/transforms.conf to remove the event data which does not contain any information in it?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398298#M94558</link>
      <description>&lt;P&gt;If you are making the events be multi-line events (one for each time the command is run), then you can use the &lt;CODE&gt;SEDCMD&lt;/CODE&gt; in &lt;CODE&gt;props.conf&lt;/CODE&gt; to remove only the header lines.&lt;/P&gt;

&lt;P&gt;If you are making each line be a separate event (as it appeared in your question), you can use something like my suggestion.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2018 19:38:09 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398298#M94558</guid>
      <dc:creator>cpetterborg</dc:creator>
      <dc:date>2018-06-20T19:38:09Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure in props/transforms.conf to remove the event data which does not contain any information in it?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398299#M94559</link>
      <description>&lt;P&gt;Hey we are splitting  multiple events in to single individual events by using the line_breaker stanza in props.conf.  And also we wanted to remove the events which does not contain any information in it.&lt;/P&gt;

&lt;P&gt;1) To split multiple events in to single individual events.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[who]
 SHOULD_LINEMERGE=false
 LINE_BREAKER=([\r\n]+)
 TRUNCATE=1000000
 DATETIME_CONFIG = CURRENT
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;2) For removing the events which does not contain any information.&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Props.conf
[who]
 TRANSFORMS-null= setnull

 Transforms.conf details:
 [setnull]
  REGEX = ^USERNAME\s+LINE\s+HOSTNAME\s+TIME$
  DEST_KEY = queue
  FORMAT = nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Kindly guide me on this. &lt;/P&gt;</description>
      <pubDate>Wed, 20 Jun 2018 19:49:18 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398299#M94559</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2018-06-20T19:49:18Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure in props/transforms.conf to remove the event data which does not contain any information in it?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398300#M94560</link>
      <description>&lt;P&gt;Give this a try (changed strategy from 'Drop specific events' to 'Keep specific event and drop remaining'). &lt;BR /&gt;
Reference: &lt;A href="http://docs.splunk.com/Documentation/Splunk/7.1.1/Forwarding/Routeandfilterdatad#Keep_specific_events_and_discard_the_rest"&gt;http://docs.splunk.com/Documentation/Splunk/7.1.1/Forwarding/Routeandfilterdatad#Keep_specific_events_and_discard_the_rest&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Edit props.conf and add the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[who]
TRANSFORMS-set= setnull,setparsing
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Edit transforms.conf and add the following:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[setnull]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue

#basically keeping anything that has header and at least one data row
[setparsing]
REGEX = ^(USERNAME).+[\r\n]+\w+
DEST_KEY = queue
FORMAT = indexQueue
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 20 Jun 2018 21:38:05 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398300#M94560</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-06-20T21:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure in props/transforms.conf to remove the event data which does not contain any information in it?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398301#M94561</link>
      <description>&lt;P&gt;Hi SomeSoni2,&lt;/P&gt;

&lt;P&gt;Yes I had given a try with the above set of configuration in my test environment by uploading the data in raw text format via Add data --&amp;gt;upload --&amp;gt; select sourcetype but it did not fetch the required output. &lt;/P&gt;

&lt;P&gt;Instead getting the below message.&lt;BR /&gt;
&lt;STRONG&gt;No results found. Please change source type, adjust source type settings, or check your source file&lt;/STRONG&gt;&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;Props.conf details:
[who]
  SHOULD_LINEMERGE=false
  LINE_BREAKER=([\r\n]+)
  TRUNCATE=1000000
  DATETIME_CONFIG = CURRENT
TRANSFORMS-set= setnull,setparsing

Transforms.conf details:
[setnull]
 REGEX = .
 DEST_KEY = queue
 FORMAT = nullQueue

 #basically keeping anything that has header and at least one data row
 [setparsing]
 REGEX = ^(USERNAME).+[\r\n]+\w+
 DEST_KEY = queue
 FORMAT = indexQueue
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Kindly guide me on this.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 09:40:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398301#M94561</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2018-06-21T09:40:22Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure in props/transforms.conf to remove the event data which does not contain any information in it?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398302#M94562</link>
      <description>&lt;P&gt;Hi Somesoni2, by applying the above stanza in props.conf and transforms.conf, the entire event information are removed from splunk and it throws the below message.&lt;/P&gt;

&lt;P&gt;No results found. Please change source type, adjust source type settings, or check your source file&lt;/P&gt;

&lt;P&gt;Could you please guide me on this to events which does not contain any information in it.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 14:50:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398302#M94562</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2018-06-21T14:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure in props/transforms.conf to remove the event data which does not contain any information in it?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398303#M94563</link>
      <description>&lt;P&gt;YOu said you're uploading it from an instance. Did you setup these (props and transforms) on the same server/instance? If this a test environment, try setting up a monitoring (using inputs.conf) and test the ingestion, instead of using Add Data wizard.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 14:58:11 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398303#M94563</guid>
      <dc:creator>somesoni2</dc:creator>
      <dc:date>2018-06-21T14:58:11Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure in props/transforms.conf to remove the event data which does not contain any information in it?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398304#M94564</link>
      <description>&lt;P&gt;thanks Somesoni2, let me try that.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 15:38:13 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398304#M94564</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2018-06-21T15:38:13Z</dc:date>
    </item>
    <item>
      <title>Re: How to configure in props/transforms.conf to remove the event data which does not contain any information in it?</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398305#M94565</link>
      <description>&lt;P&gt;Hey it did not work,  could you please guide me on this &lt;/P&gt;

&lt;P&gt;USERNAME        LINE        HOSTNAME                                  TIME&lt;/P&gt;

&lt;P&gt;host =  tt3crp00 source =   who sourcetype =    who&lt;/P&gt;

&lt;P&gt;6/21/18&lt;BR /&gt;
1:11:25.000 PM&lt;BR /&gt;&lt;BR /&gt;
USERNAME        LINE        HOSTNAME                                  TIME&lt;/P&gt;

&lt;P&gt;solarwinds      pts/21      vmswpep02.XXXX.com                    Jun 21 13:11&lt;/P&gt;

&lt;P&gt;host =  tt3dev00 source =   who sourcetype =    who&lt;/P&gt;

&lt;P&gt;6/21/18&lt;BR /&gt;
1:11:25.000 PM  &lt;/P&gt;

&lt;P&gt;USERNAME        LINE        HOSTNAME                                  TIME&lt;BR /&gt;
solarwinds      pts/0       vmswpep05.xxxx.com                    2018-06-21 13:11&lt;BR /&gt;
solarwinds      pts/1       vmswpep05.xxxx.com                    2018-06-21 13:11&lt;/P&gt;

&lt;P&gt;the above props/transforms.conf are placed in the Heavy forwarder instances.&lt;/P&gt;

&lt;P&gt;Kindly guide me to fix this issue. &lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 17:26:12 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/How-to-configure-in-props-transforms-conf-to-remove-the-event/m-p/398305#M94565</guid>
      <dc:creator>Hemnaath</dc:creator>
      <dc:date>2018-06-21T17:26:12Z</dc:date>
    </item>
  </channel>
</rss>

