All Apps and Add-ons

How to remove fields with Zero value, in events of Firepower eStreamer?

jfeitosa_real
Path Finder

Hi guys!

Below a sample log, fields with values 00000 wanted to discard without losing the other fields. It's possible? How to make?

ssl_session_id=0000000000000000000000000000000000000000000000000000000000000000 monitor_rule_6=N/A src_tos=0 referenced_host="" iface_egress=inside ssl_flow_messages=0 src_ip_country=unknown dns_query="" sec_intel_event=No sinkhole_uuid=00000000-0000-0000-0000-000000000000 user=Unknown sec_zone_ingress=N/A ssl_url_category=0 fw_rule_reason=N/A src_pkts=2 netflow_src=00000000-0000-0000-0000-000000000000 event_desc="Flow Statistics" ssl_flow_flags=0 ssl_policy_id=00000000000000000000000000000000 mac_address=00:00:00:00:00:00 ssl_ticket_id=0000000000000000000000000000000000000000 rec_type_simple=RNA rec_type_desc="Connection Statistics" iface_ingress=antena security_context=00000000000000000000000000000000 snmp_in=0 dest_tos=0 src_mask=0 http_response=0 ssl_server_name="" dest_mask=0 client_version="" dns_resp_id=0 ssl_cert_fingerprint=0000000000000000000000000000000000000000 last_pkt_sec=0

Thanks a lot!
James

0 Karma

douglashurd
Builder

The TA simply forwards what its collected from the FMC. I'm not sure there is any practical way to address this short of customizing the TA to delete specific fields. I'll do a little more research.

0 Karma

jfeitosa_real
Path Finder

Hi people!

Can someone help with this issue?

Thanks

0 Karma
Get Updates on the Splunk Community!

How I Instrumented a Rust Application Without Knowing Rust

As a technical writer, I often have to edit or create code snippets for Splunk's distributions of ...

Splunk Community Platform Survey

Hey Splunk Community, Starting today, the community platform may prompt you to participate in a survey. The ...

Observability Highlights | November 2022 Newsletter

 November 2022Observability CloudEnd Of Support Extension for SignalFx Smart AgentSplunk is extending the End ...