All Apps and Add-ons

How to remove fields with Zero value, in events of Firepower eStreamer?

jfeitosa_real
Path Finder

Hi guys!

Below a sample log, fields with values 00000 wanted to discard without losing the other fields. It's possible? How to make?

ssl_session_id=0000000000000000000000000000000000000000000000000000000000000000 monitor_rule_6=N/A src_tos=0 referenced_host="" iface_egress=inside ssl_flow_messages=0 src_ip_country=unknown dns_query="" sec_intel_event=No sinkhole_uuid=00000000-0000-0000-0000-000000000000 user=Unknown sec_zone_ingress=N/A ssl_url_category=0 fw_rule_reason=N/A src_pkts=2 netflow_src=00000000-0000-0000-0000-000000000000 event_desc="Flow Statistics" ssl_flow_flags=0 ssl_policy_id=00000000000000000000000000000000 mac_address=00:00:00:00:00:00 ssl_ticket_id=0000000000000000000000000000000000000000 rec_type_simple=RNA rec_type_desc="Connection Statistics" iface_ingress=antena security_context=00000000000000000000000000000000 snmp_in=0 dest_tos=0 src_mask=0 http_response=0 ssl_server_name="" dest_mask=0 client_version="" dns_resp_id=0 ssl_cert_fingerprint=0000000000000000000000000000000000000000 last_pkt_sec=0

Thanks a lot!
James

0 Karma

douglashurd
Builder

The TA simply forwards what its collected from the FMC. I'm not sure there is any practical way to address this short of customizing the TA to delete specific fields. I'll do a little more research.

0 Karma

jfeitosa_real
Path Finder

Hi people!

Can someone help with this issue?

Thanks

0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...