<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Filtering event on splunk fowarder in Getting Data In</title>
    <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-event-on-splunk-fowarder/m-p/49984#M9513</link>
    <description>&lt;P&gt;Well i didn't see this page, thanks.&lt;/P&gt;

&lt;P&gt;But i want to do this on a UniversalSplunkFowarder, not a heavy fowarder which is i guess a physical splunk appliance, correct ?&lt;/P&gt;</description>
    <pubDate>Tue, 04 Sep 2012 09:26:22 GMT</pubDate>
    <dc:creator>rbw78</dc:creator>
    <dc:date>2012-09-04T09:26:22Z</dc:date>
    <item>
      <title>Filtering event on splunk fowarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-event-on-splunk-fowarder/m-p/49982#M9511</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;

&lt;P&gt;Here's the situation.&lt;BR /&gt;
I have an equipement sending 2 kinds of events with UDP syslog to a splunk fowarder and then  send it to a splunk server in TCP.&lt;BR /&gt;
I would like to filter events on the splunk fowarder with the outputs.conf or inputs.conf files by gathering only 1 kind of log.&lt;BR /&gt;
i'd see this is possible on the splunk server directly but i want to minimize the impact on the bandwidth and not sending useless logs for nothing.&lt;/P&gt;

&lt;P&gt;Is there a way to do that via a regex or specific char on the event ?&lt;/P&gt;

&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Mon, 03 Sep 2012 14:43:55 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-event-on-splunk-fowarder/m-p/49982#M9511</guid>
      <dc:creator>rbw78</dc:creator>
      <dc:date>2012-09-03T14:43:55Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering event on splunk fowarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-event-on-splunk-fowarder/m-p/49983#M9512</link>
      <description>&lt;P&gt;Have you read .... &lt;A href="http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Routeandfilterdatad"&gt;http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Routeandfilterdatad&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;This should get you going? should be fairly simple if you know what you want to exclude&lt;/P&gt;</description>
      <pubDate>Mon, 03 Sep 2012 14:51:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-event-on-splunk-fowarder/m-p/49983#M9512</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-09-03T14:51:22Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering event on splunk fowarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-event-on-splunk-fowarder/m-p/49984#M9513</link>
      <description>&lt;P&gt;Well i didn't see this page, thanks.&lt;/P&gt;

&lt;P&gt;But i want to do this on a UniversalSplunkFowarder, not a heavy fowarder which is i guess a physical splunk appliance, correct ?&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2012 09:26:22 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-event-on-splunk-fowarder/m-p/49984#M9513</guid>
      <dc:creator>rbw78</dc:creator>
      <dc:date>2012-09-04T09:26:22Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering event on splunk fowarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-event-on-splunk-fowarder/m-p/49985#M9514</link>
      <description>&lt;P&gt;basically no, Splunk do not have any appliances, the "Heavy" forwarder is simply a regular instance of Splunk that has forwarding enabled... to add some more info a "Light" forwarder is a regular instance of Splunk that has some features disabled such as Splunkweb and indexing. And "Universal" forwarder is a completely stripped down instance of Splunk with no webUI, no python etc. Unfortunately as the docs say unless you simply want to filter on the metadata of host/source/sourcetype, you can not use a light or universal forwarder (i.e. for your event filtering).&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2012 09:45:58 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-event-on-splunk-fowarder/m-p/49985#M9514</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-09-04T09:45:58Z</dc:date>
    </item>
    <item>
      <title>Re: Filtering event on splunk fowarder</title>
      <link>https://community.splunk.com/t5/Getting-Data-In/Filtering-event-on-splunk-fowarder/m-p/49986#M9515</link>
      <description>&lt;P&gt;so they are all just applications that run on top of another platform&lt;/P&gt;</description>
      <pubDate>Tue, 04 Sep 2012 09:46:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Getting-Data-In/Filtering-event-on-splunk-fowarder/m-p/49986#M9515</guid>
      <dc:creator>MHibbin</dc:creator>
      <dc:date>2012-09-04T09:46:31Z</dc:date>
    </item>
  </channel>
</rss>

