All Apps and Add-ons

How to remove fields with Zero value, in events of Firepower eStreamer?

jfeitosa_real
Path Finder

Hi guys!

Below a sample log, fields with values 00000 wanted to discard without losing the other fields. It's possible? How to make?

ssl_session_id=0000000000000000000000000000000000000000000000000000000000000000 monitor_rule_6=N/A src_tos=0 referenced_host="" iface_egress=inside ssl_flow_messages=0 src_ip_country=unknown dns_query="" sec_intel_event=No sinkhole_uuid=00000000-0000-0000-0000-000000000000 user=Unknown sec_zone_ingress=N/A ssl_url_category=0 fw_rule_reason=N/A src_pkts=2 netflow_src=00000000-0000-0000-0000-000000000000 event_desc="Flow Statistics" ssl_flow_flags=0 ssl_policy_id=00000000000000000000000000000000 mac_address=00:00:00:00:00:00 ssl_ticket_id=0000000000000000000000000000000000000000 rec_type_simple=RNA rec_type_desc="Connection Statistics" iface_ingress=antena security_context=00000000000000000000000000000000 snmp_in=0 dest_tos=0 src_mask=0 http_response=0 ssl_server_name="" dest_mask=0 client_version="" dns_resp_id=0 ssl_cert_fingerprint=0000000000000000000000000000000000000000 last_pkt_sec=0

Thanks a lot!
James

0 Karma

douglashurd
Builder

The TA simply forwards what its collected from the FMC. I'm not sure there is any practical way to address this short of customizing the TA to delete specific fields. I'll do a little more research.

0 Karma

jfeitosa_real
Path Finder

Hi people!

Can someone help with this issue?

Thanks

0 Karma
Get Updates on the Splunk Community!

Welcome to the Splunk Community!

(view in My Videos) We're so glad you're here! The Splunk Community is place to connect, learn, give back, and ...

Tech Talk | Elevating Digital Service Excellence: The Synergy of Splunk RUM & APM

Elevating Digital Service Excellence: The Synergy of Real User Monitoring and Application Performance ...

Adoption of RUM and APM at Splunk

    Unleash the power of Splunk Observability   Watch Now In this can't miss Tech Talk! The Splunk Growth ...