<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Discarding Specific type of traffic either on forwarder or indexer fails in Splunk Enterprise Security</title>
    <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Discarding-Specific-type-of-traffic-either-on-forwarder-or/m-p/497361#M8655</link>
    <description>&lt;P&gt;please try this one: &lt;A href="https://regex101.com/r/wgNicw/1"&gt;https://regex101.com/r/wgNicw/1&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;transforms.conf&lt;BR /&gt;
[discardsnmp]&lt;BR /&gt;
REGEX = \b(\w[a-zA-Z].*\Dapp=SNMP.+)&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = nullQueue&lt;/P&gt;</description>
    <pubDate>Tue, 15 Oct 2019 00:15:06 GMT</pubDate>
    <dc:creator>ivanreis</dc:creator>
    <dc:date>2019-10-15T00:15:06Z</dc:date>
    <item>
      <title>Discarding Specific type of traffic either on forwarder or indexer fails</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Discarding-Specific-type-of-traffic-either-on-forwarder-or/m-p/497360#M8654</link>
      <description>&lt;P&gt;Discarding Specific type of traffic either on forwarder or indexer fails, I tried to discard it using blacklist on forwarder and nullqueue transform on indexer and both failed.&lt;/P&gt;

&lt;P&gt;here is a log sample&lt;/P&gt;

&lt;P&gt;Oct  3 11:34:03 1.1.1.1 CEF:0|FORCEPOINT|Firewall|6.5.1|70018|Connection_Allowed|0|app=SNMP (UDP) rt=Oct 03 2019 11:28:12 deviceFacility=Packet Filtering act=Allow deviceOutboundInterface=13 deviceInboundInterface=0 proto=17 dpt=161 spt=62032 dst=2.2.2.2 src=3.3.3.3 dvchost=4.4.4.4 dvc=4.4.4.4 deviceExternalId=company-name node 1 cs1Label=RuleID cs1=2097272.10&lt;/P&gt;

&lt;P&gt;and the configuration&lt;/P&gt;

&lt;P&gt;props.conf&lt;BR /&gt;
[forcepoint]&lt;BR /&gt;
Transform-Forcepoint=discardsnmp&lt;/P&gt;

&lt;P&gt;transforms.conf&lt;BR /&gt;
[discardsnmp]&lt;BR /&gt;
REGEX = app=&lt;EM&gt;SNMP&lt;/EM&gt;&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = nullQueue&lt;/P&gt;

&lt;P&gt;any one can find out what is the problem?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Oct 2019 08:42:28 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Discarding-Specific-type-of-traffic-either-on-forwarder-or/m-p/497360#M8654</guid>
      <dc:creator>abwe</dc:creator>
      <dc:date>2019-10-03T08:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: Discarding Specific type of traffic either on forwarder or indexer fails</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Discarding-Specific-type-of-traffic-either-on-forwarder-or/m-p/497361#M8655</link>
      <description>&lt;P&gt;please try this one: &lt;A href="https://regex101.com/r/wgNicw/1"&gt;https://regex101.com/r/wgNicw/1&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;transforms.conf&lt;BR /&gt;
[discardsnmp]&lt;BR /&gt;
REGEX = \b(\w[a-zA-Z].*\Dapp=SNMP.+)&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = nullQueue&lt;/P&gt;</description>
      <pubDate>Tue, 15 Oct 2019 00:15:06 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Discarding-Specific-type-of-traffic-either-on-forwarder-or/m-p/497361#M8655</guid>
      <dc:creator>ivanreis</dc:creator>
      <dc:date>2019-10-15T00:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: Discarding Specific type of traffic either on forwarder or indexer fails</title>
      <link>https://community.splunk.com/t5/Splunk-Enterprise-Security/Discarding-Specific-type-of-traffic-either-on-forwarder-or/m-p/497362#M8656</link>
      <description>&lt;P&gt;Thanks, it worked like charm&lt;/P&gt;</description>
      <pubDate>Sun, 20 Oct 2019 09:34:40 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Enterprise-Security/Discarding-Specific-type-of-traffic-either-on-forwarder-or/m-p/497362#M8656</guid>
      <dc:creator>abwe</dc:creator>
      <dc:date>2019-10-20T09:34:40Z</dc:date>
    </item>
  </channel>
</rss>

