<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to use regex to send events to NullQueue? in Splunk Search</title>
    <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332229#M98857</link>
    <description>&lt;P&gt;nope, but you cannot use &lt;CODE&gt;[monitor://...]&lt;/CODE&gt; in &lt;CODE&gt;props.conf&lt;/CODE&gt; like @ddrillic wrote, it must be either a host, a source, or a sourcetype in the stanza.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
    <pubDate>Tue, 10 Jul 2018 21:43:23 GMT</pubDate>
    <dc:creator>MuS</dc:creator>
    <dc:date>2018-07-10T21:43:23Z</dc:date>
    <item>
      <title>How to use regex to send events to NullQueue?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332224#M98852</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;

&lt;P&gt;How to use regex to send all events related to fw_rule=0 and from a sensor  sensor=abcd-f01 to null queue?&lt;/P&gt;

&lt;P&gt;sample event:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;rec_type=71 app_proto=Unknown client_app=Unknown client_version="" connection_id=0 dest_autonomous_system=0 dest_bytes=0 dest_ip=1.2.3.4 dest_ip_country=0 dest_mask=0 dest_pkts=0 dest_port=80 dest_tos=0 dns_query="" dns_rec_id=0 dns_resp_id=0 dns_ttl=0 event_desc="Flow Statistics" event_sec=1523461342 event_subtype=1 event_type=1003 event_usec=0 file_count=0 first_pkt_sec=1523461341 fw_policy=F01_POLICY fw_rule=0 fw_rule_action=Fastpath fw_rule_reason=N/A has_ipv6=1 http_referrer="" http_response=0 iface_egress=1.2 iface_ingress=P2.3 instance_id=0 ip_layer=0 ip_proto=TCP ips_count=0 last_pkt_sec=0 legacy_ip_address=0.0.0.0 mac_address=0:0:0:0:0:0 monitor_rule_1=N/A monitor_rule_2=N/A monitor_rule_3=N/A monitor_rule_4=N/A monitor_rule_5=N/A monitor_rule_6=N/A monitor_rule_7=N/A monitor_rule_8=0 netbios_domain="" netflow_src=00000000-0000-0000-0000-000000000000 num_ioc=0 rec_type_desc="Connection Statistics" rec_type_simple=RNA referenced_host="" sec_intel_event=No sec_intel_ip=N/A sec_zone_egress=F01_OUTSIDE sec_zone_ingress=F01_INSIDE security_context=00000000000000000000000000000000 sensor=abcd-f01 sinkhole_uuid=00000000-0000-0000-0000-000000000000 snmp_in=0 snmp_out=0 src_autonomous_system=0 src_bytes=0 src_ip=22.33.44.55 src_ip_country=unknown src_mask=0 src_pkts=0 src_port=4382 src_tos=0 ssl_actual_action=Unknown ssl_cert_fingerprint=0000000000000000000000000000000000000000 ssl_cipher_suite=TLS_NULL_WITH_NULL_NULL ssl_expected_action=Unknown ssl_flow_error=0 ssl_flow_flags=0 ssl_flow_messages=0 ssl_flow_status=Unknown ssl_policy_id=00000000000000000000000000000000 ssl_rule_id=0 ssl_server_cert_status="Not Checked" ssl_server_name="" ssl_session_id=0000000000000000000000000000000000000000000000000000000000000000 ssl_ticket_id=0000000000000000000000000000000000000000 ssl_url_category=0 ssl_version=Unknown tcp_flags=0 url="" url_category=Unknown url_reputation="Risk unknown" user="No Authentication Required" user_agent="" vlan_id=0 web_app=Unknown
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;I tried below in config, it's not working.Is there anything I have to add.&lt;/P&gt;

&lt;P&gt;props.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[cisco:estreamer:data]
TRANSFORMS-null= setnull
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;transforms.conf&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[setnull]
SOURCE_KEY=_raw
REGEX = (fw_rule=0.*sensor=abcd-f01)
DEST_KEY = queue
FORMAT = nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 11 Apr 2018 16:12:51 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332224#M98852</guid>
      <dc:creator>kiran331</dc:creator>
      <dc:date>2018-04-11T16:12:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to use regex to send events to NullQueue?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332225#M98853</link>
      <description>&lt;P&gt;Can you try :&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[setnull]
 REGEX = fw_rule=0.*sensor=abcd-f01
 DEST_KEY = queue
 FORMAT = nullQueue
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Thu, 12 Apr 2018 05:12:30 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332225#M98853</guid>
      <dc:creator>p_gurav</dc:creator>
      <dc:date>2018-04-12T05:12:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to use regex to send events to NullQueue?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332226#M98854</link>
      <description>&lt;P&gt;I want to forward "Security Intelligence Events", props.conf and transforms.conf are saved in "/opt/splunk/etc/apps/TA-eStreamer/local"&lt;/P&gt;

&lt;P&gt;props.conf&lt;BR /&gt;
[monitor://$SPLUNK_HOME/etc/apps/TA-eStreamer/data]&lt;BR /&gt;
TRANSFORMS-set = setnull&lt;/P&gt;

&lt;P&gt;Transforms.conf&lt;BR /&gt;
 [setnull]&lt;BR /&gt;
 REGEX = (sec_intel_event=Yes)&lt;BR /&gt;
 DEST_KEY = queue&lt;BR /&gt;
 FORMAT = nullQueue&lt;/P&gt;

&lt;P&gt;But it doesn't work, who can help me? Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:19:25 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332226#M98854</guid>
      <dc:creator>haoban</dc:creator>
      <dc:date>2020-09-29T20:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to use regex to send events to NullQueue?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332227#M98855</link>
      <description>&lt;P&gt;In &lt;CODE&gt;props.conf&lt;/CODE&gt; something like -&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt;[&amp;lt;sourcetype&amp;gt;]    -- the sourcetype which corresponds to monitor://$SPLUNK_HOME/etc/apps/TA-eStreamer/data
TRANSFORMS = setnull
&lt;/CODE&gt;&lt;/PRE&gt;</description>
      <pubDate>Wed, 04 Jul 2018 17:24:42 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332227#M98855</guid>
      <dc:creator>ddrillic</dc:creator>
      <dc:date>2018-07-04T17:24:42Z</dc:date>
    </item>
    <item>
      <title>Re: How to use regex to send events to NullQueue?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332228#M98856</link>
      <description>&lt;P&gt;Do I need to escap the "=" in REGEX such as "REGEX = (sec_intel_event=Yes)"&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:22:47 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332228#M98856</guid>
      <dc:creator>haoban</dc:creator>
      <dc:date>2020-09-29T20:22:47Z</dc:date>
    </item>
    <item>
      <title>Re: How to use regex to send events to NullQueue?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332229#M98857</link>
      <description>&lt;P&gt;nope, but you cannot use &lt;CODE&gt;[monitor://...]&lt;/CODE&gt; in &lt;CODE&gt;props.conf&lt;/CODE&gt; like @ddrillic wrote, it must be either a host, a source, or a sourcetype in the stanza.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 21:43:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332229#M98857</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2018-07-10T21:43:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to use regex to send events to NullQueue?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332230#M98858</link>
      <description>&lt;P&gt;I changed the props.conf and transforms.conf as following. But seems no event is forwarded.&lt;BR /&gt;
===props.conf===&lt;BR /&gt;
[cisco:estreamer:data]&lt;BR /&gt;
TRANSFORMS = setnull&lt;/P&gt;

&lt;P&gt;===transforms.conf===&lt;BR /&gt;
[setnull]&lt;BR /&gt;
REGEX = (sec_intel_event=Yes)&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = nullQueue&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:22:50 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332230#M98858</guid>
      <dc:creator>haoban</dc:creator>
      <dc:date>2020-09-29T20:22:50Z</dc:date>
    </item>
    <item>
      <title>Re: How to use regex to send events to NullQueue?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332231#M98859</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;

&lt;P&gt;the &lt;CODE&gt;props.conf&lt;/CODE&gt; entry for the TRANSFORMS looks wrong, try something like:&lt;/P&gt;

&lt;PRE&gt;&lt;CODE&gt; TRANSFORMS-send-data-to-null-queue = setnull
&lt;/CODE&gt;&lt;/PRE&gt;

&lt;P&gt;Also, remember that this must be on the parsing Splunk instance, it needs a restart after the change, and it will only work for new events.&lt;/P&gt;

&lt;P&gt;cheers, MuS&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jul 2018 22:19:14 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332231#M98859</guid>
      <dc:creator>MuS</dc:creator>
      <dc:date>2018-07-10T22:19:14Z</dc:date>
    </item>
    <item>
      <title>Re: How to use regex to send events to NullQueue?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332232#M98860</link>
      <description>&lt;P&gt;props.conf and transforms.conf are in &lt;STRONG&gt;heavy forwarder&lt;/STRONG&gt;. Still not working, all "cisco:estreamer:data" forwarded to the indexer. I only want "&lt;STRONG&gt;sec_intel_event=Yes&lt;/STRONG&gt;" forward to indexer.&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;/opt/splunk/etc/apps/TA-eStreamer/local&lt;/STRONG&gt;# cat props.conf&lt;BR /&gt;
[cisco:estreamer:data]&lt;BR /&gt;
TRANSFORMS-send-data-to-null-queue = setnull&lt;/P&gt;

&lt;P&gt;&lt;STRONG&gt;/opt/splunk/etc/apps/TA-eStreamer/local&lt;/STRONG&gt;# cat transforms.conf&lt;BR /&gt;
[setnull]&lt;BR /&gt;
REGEX = (sec_intel_event=Yes)&lt;BR /&gt;
DEST_KEY = queue&lt;BR /&gt;
FORMAT = nullQueue&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:23:23 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332232#M98860</guid>
      <dc:creator>haoban</dc:creator>
      <dc:date>2020-09-29T20:23:23Z</dc:date>
    </item>
    <item>
      <title>Re: How to use regex to send events to NullQueue?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332233#M98861</link>
      <description>&lt;P&gt;I made a stupid mistake. The NullQueue is like drop something. So the the REGEX should be "sec_intel_event=No'.&lt;/P&gt;

&lt;P&gt;Thanks all your help, guys!&lt;/P&gt;</description>
      <pubDate>Tue, 29 Sep 2020 20:23:26 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/332233#M98861</guid>
      <dc:creator>haoban</dc:creator>
      <dc:date>2020-09-29T20:23:26Z</dc:date>
    </item>
    <item>
      <title>Re: How to use regex to send events to NullQueue?</title>
      <link>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/628795#M218423</link>
      <description>&lt;PRE&gt;[setnull]&lt;/PRE&gt;&lt;P&gt;Do not use stansa name like this.&amp;nbsp; What happens if you have two app with samme stansa name, it may give you problem&lt;/P&gt;&lt;P&gt;Use f.eks.&amp;nbsp;&lt;/P&gt;&lt;P&gt;[remove_firewall_sensor_abcd]&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 30 Jan 2023 07:55:53 GMT</pubDate>
      <guid>https://community.splunk.com/t5/Splunk-Search/How-to-use-regex-to-send-events-to-NullQueue/m-p/628795#M218423</guid>
      <dc:creator>jotne</dc:creator>
      <dc:date>2023-01-30T07:55:53Z</dc:date>
    </item>
  </channel>
</rss>

