<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How do you discard events from the cron.log? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-discard-events-from-the-cron-log/m-p/431230#M123263</link>
    <description>&lt;P&gt;Did you make this configuration on your Universal Forwarder?&lt;/P&gt;

&lt;P&gt;I am asking this because the documentation on &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/Forwarding/Routeandfilterdatad"&gt;Route and filter data&lt;/A&gt; says:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;You can use heavy forwarders to filter and route event data to Splunk instances.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;So I believe that these kind of filters are not working on Universal Forwarders.&lt;/P&gt;

&lt;P&gt;I suggest you put this configuration on the system which comes after the Universal Forwarder (probably a Heavy Forwarder or an Indexer) or replace the Universal Forwarder installation with a Heavy Forwarder.&lt;/P&gt;</description>
    <pubDate>Tue, 29 Jan 2019 14:39:37 GMT</pubDate>
    <dc:creator>whrg</dc:creator>
    <dc:date>2019-01-29T14:39:37Z</dc:date>
    <item>
      <title>How do you discard events from the cron.log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-discard-events-from-the-cron-log/m-p/431228#M123261</link>
      <description>&lt;P&gt;On my universal forwarder, I have a repeated entry in my cron.log file that I would like to discard. However, I am not very familiar with regex terms.  The entry in the cron.log is: &lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;hostname  CROND[27158]: (root) CMD (/bin/sh /etc/init.d/swiagentd swrestart &amp;gt; /dev/null 2&amp;amp;&amp;gt;1)
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I have followed the instructions at:&lt;/P&gt;

&lt;P&gt;&lt;A href="https://docs.splunk.com/Documentation/Splunk/6.5.2/Forwarding/Routeandfilterdatad#Discard_specific_events_and_keep_the_rest"&gt;https://docs.splunk.com/Documentation/Splunk/6.5.2/Forwarding/Routeandfilterdatad#Discard_specific_events_and_keep_the_rest&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;and I am using the following:&lt;/P&gt;

&lt;P&gt;props.conf&lt;BR /&gt;
[source::/var/log/cron]&lt;BR /&gt;
TRANSFORMS-null= setnull&lt;/P&gt;

&lt;P&gt;transforms.conf&lt;BR /&gt;
[setnull]&lt;BR /&gt;
REGEX = swrestart&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = nullQueue&lt;/P&gt;

&lt;P&gt;I have restarted but I am still getting the message in my search.  Do I have the correct regex?  And is there a specific place in each .conf file that I should put the stanzas?&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 12:11:04 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-discard-events-from-the-cron-log/m-p/431228#M123261</guid>
      <dc:creator>scamarda</dc:creator>
      <dc:date>2019-01-29T12:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: How do you discard events from the cron.log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-discard-events-from-the-cron-log/m-p/431229#M123262</link>
      <description>&lt;P&gt;HI,&lt;/P&gt;

&lt;P&gt;is /var/log/cron the source which is displayed with this events? Could it be that it is /var/log/cron.log&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 12:56:08 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-discard-events-from-the-cron-log/m-p/431229#M123262</guid>
      <dc:creator>dkeck</dc:creator>
      <dc:date>2019-01-29T12:56:08Z</dc:date>
    </item>
    <item>
      <title>Re: How do you discard events from the cron.log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-discard-events-from-the-cron-log/m-p/431230#M123263</link>
      <description>&lt;P&gt;Did you make this configuration on your Universal Forwarder?&lt;/P&gt;

&lt;P&gt;I am asking this because the documentation on &lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/Forwarding/Routeandfilterdatad"&gt;Route and filter data&lt;/A&gt; says:&lt;/P&gt;

&lt;BLOCKQUOTE&gt;
&lt;P&gt;You can use heavy forwarders to filter and route event data to Splunk instances.&lt;/P&gt;
&lt;/BLOCKQUOTE&gt;

&lt;P&gt;So I believe that these kind of filters are not working on Universal Forwarders.&lt;/P&gt;

&lt;P&gt;I suggest you put this configuration on the system which comes after the Universal Forwarder (probably a Heavy Forwarder or an Indexer) or replace the Universal Forwarder installation with a Heavy Forwarder.&lt;/P&gt;</description>
      <pubDate>Tue, 29 Jan 2019 14:39:37 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-discard-events-from-the-cron-log/m-p/431230#M123263</guid>
      <dc:creator>whrg</dc:creator>
      <dc:date>2019-01-29T14:39:37Z</dc:date>
    </item>
    <item>
      <title>Re: How do you discard events from the cron.log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-discard-events-from-the-cron-log/m-p/431231#M123264</link>
      <description>&lt;P&gt;@scamarda if you want to do parsing of the input, you have to do it either on Heavy Forwarder or on Indexer.&lt;BR /&gt;
Universal Forwarder is not capable of parsing or transforms.&lt;/P&gt;

&lt;P&gt;The some good reading about it:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/Deploy/Datapipeline"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.3/Deploy/Datapipeline&lt;/A&gt;&lt;BR /&gt;
and subsequently next page:&lt;BR /&gt;
&lt;A href="https://docs.splunk.com/Documentation/Splunk/7.2.3/Deploy/Componentsofadistributedenvironment"&gt;https://docs.splunk.com/Documentation/Splunk/7.2.3/Deploy/Componentsofadistributedenvironment&lt;/A&gt;&lt;/P&gt;

&lt;P&gt;Other interesting article about where to configure what in the data pipeline and for which part of the pipeline is here:&lt;BR /&gt;
&lt;A href="https://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings"&gt;https://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 17:59:29 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-discard-events-from-the-cron-log/m-p/431231#M123264</guid>
      <dc:creator>petom</dc:creator>
      <dc:date>2019-01-30T17:59:29Z</dc:date>
    </item>
    <item>
      <title>Re: How do you discard events from the cron.log?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-do-you-discard-events-from-the-cron-log/m-p/431232#M123265</link>
      <description>&lt;P&gt;You need to deploy this to the first full instance of Splunk that handles the data (either HF or Indexer tier).  You need to restart all Splunk instances there.  You need to forward in NEW data (old data will remain) so add &lt;CODE&gt;_index_earliest=-5m&lt;/CODE&gt; to your &lt;CODE&gt;All time&lt;/CODE&gt; search.&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jan 2019 19:30:31 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-do-you-discard-events-from-the-cron-log/m-p/431232#M123265</guid>
      <dc:creator>woodcock</dc:creator>
      <dc:date>2019-01-30T19:30:31Z</dc:date>
    </item>
  </channel>
</rss>

