All Apps and Add-ons

How to remove fields with Zero value, in events of Firepower eStreamer?

jfeitosa_real
Path Finder

Hi guys!

Below a sample log, fields with values 00000 wanted to discard without losing the other fields. It's possible? How to make?

ssl_session_id=0000000000000000000000000000000000000000000000000000000000000000 monitor_rule_6=N/A src_tos=0 referenced_host="" iface_egress=inside ssl_flow_messages=0 src_ip_country=unknown dns_query="" sec_intel_event=No sinkhole_uuid=00000000-0000-0000-0000-000000000000 user=Unknown sec_zone_ingress=N/A ssl_url_category=0 fw_rule_reason=N/A src_pkts=2 netflow_src=00000000-0000-0000-0000-000000000000 event_desc="Flow Statistics" ssl_flow_flags=0 ssl_policy_id=00000000000000000000000000000000 mac_address=00:00:00:00:00:00 ssl_ticket_id=0000000000000000000000000000000000000000 rec_type_simple=RNA rec_type_desc="Connection Statistics" iface_ingress=antena security_context=00000000000000000000000000000000 snmp_in=0 dest_tos=0 src_mask=0 http_response=0 ssl_server_name="" dest_mask=0 client_version="" dns_resp_id=0 ssl_cert_fingerprint=0000000000000000000000000000000000000000 last_pkt_sec=0

Thanks a lot!
James

0 Karma

douglashurd
Builder

The TA simply forwards what its collected from the FMC. I'm not sure there is any practical way to address this short of customizing the TA to delete specific fields. I'll do a little more research.

0 Karma

jfeitosa_real
Path Finder

Hi people!

Can someone help with this issue?

Thanks

0 Karma
Get Updates on the Splunk Community!

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...