<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Filter DNS debug log at index in Monitoring Splunk</title>
    <link>https://community.splunk.com/t5/Monitoring-Splunk/Filter-DNS-debug-log-at-index/m-p/62929#M7174</link>
    <description>&lt;P&gt;Hi henocqr&lt;/P&gt;

&lt;P&gt;your regex to pick up NOERROR would be &lt;CODE&gt;NOERROR&lt;/CODE&gt;, but I think you want to pick up each event which contains NOERROR and route it to the null queue, right?&lt;BR /&gt;
then the regex would be &lt;CODE&gt;.*NOERROR.*&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;cheers&lt;/P&gt;</description>
    <pubDate>Thu, 02 Feb 2012 13:46:47 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2012-02-02T13:46:47Z</dc:date>
    <item>
      <title>Filter DNS debug log at index</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Filter-DNS-debug-log-at-index/m-p/62928#M7173</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;

&lt;P&gt;I want to drop resolved DNS requests at index time.&lt;/P&gt;

&lt;P&gt;Windows 2008 DNS log format using Splunk 4.3&lt;/P&gt;

&lt;P&gt;Can anyone help me with the REGEX to pick up NOERROR from log format:-&lt;/P&gt;

&lt;P&gt;02/02/2012 11:19:06 1CB4 PACKET 0000000003C7A6C0 UDP Rcv 10.112.89.5 a3df Q [1001 D NOERROR] PTR .....&lt;/P&gt;

&lt;P&gt;I plan to send to null queue using props &amp;amp; tranforms.&lt;/P&gt;

&lt;P&gt;Thanks&lt;BR /&gt;
Ray&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2012 11:51:03 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Filter-DNS-debug-log-at-index/m-p/62928#M7173</guid>
      <dc:creator>henocqr</dc:creator>
      <dc:date>2012-02-02T11:51:03Z</dc:date>
    </item>
    <item>
      <title>Re: Filter DNS debug log at index</title>
      <link>https://community.splunk.com/t5/Monitoring-Splunk/Filter-DNS-debug-log-at-index/m-p/62929#M7174</link>
      <description>&lt;P&gt;Hi henocqr&lt;/P&gt;

&lt;P&gt;your regex to pick up NOERROR would be &lt;CODE&gt;NOERROR&lt;/CODE&gt;, but I think you want to pick up each event which contains NOERROR and route it to the null queue, right?&lt;BR /&gt;
then the regex would be &lt;CODE&gt;.*NOERROR.*&lt;/CODE&gt;&lt;/P&gt;

&lt;P&gt;cheers&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2012 13:46:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Monitoring-Splunk/Filter-DNS-debug-log-at-index/m-p/62929#M7174</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2012-02-02T13:46:47Z</dc:date>
    </item>
  </channel>
</rss>

