All Apps and Add-ons

How to remove fields with Zero value, in events of Firepower eStreamer?

jfeitosa_real
Path Finder

Hi guys!

Below a sample log, fields with values 00000 wanted to discard without losing the other fields. It's possible? How to make?

ssl_session_id=0000000000000000000000000000000000000000000000000000000000000000 monitor_rule_6=N/A src_tos=0 referenced_host="" iface_egress=inside ssl_flow_messages=0 src_ip_country=unknown dns_query="" sec_intel_event=No sinkhole_uuid=00000000-0000-0000-0000-000000000000 user=Unknown sec_zone_ingress=N/A ssl_url_category=0 fw_rule_reason=N/A src_pkts=2 netflow_src=00000000-0000-0000-0000-000000000000 event_desc="Flow Statistics" ssl_flow_flags=0 ssl_policy_id=00000000000000000000000000000000 mac_address=00:00:00:00:00:00 ssl_ticket_id=0000000000000000000000000000000000000000 rec_type_simple=RNA rec_type_desc="Connection Statistics" iface_ingress=antena security_context=00000000000000000000000000000000 snmp_in=0 dest_tos=0 src_mask=0 http_response=0 ssl_server_name="" dest_mask=0 client_version="" dns_resp_id=0 ssl_cert_fingerprint=0000000000000000000000000000000000000000 last_pkt_sec=0

Thanks a lot!
James

0 Karma

douglashurd
Builder

The TA simply forwards what its collected from the FMC. I'm not sure there is any practical way to address this short of customizing the TA to delete specific fields. I'll do a little more research.

0 Karma

jfeitosa_real
Path Finder

Hi people!

Can someone help with this issue?

Thanks

0 Karma
Get Updates on the Splunk Community!

Index This | Why did the turkey cross the road?

November 2025 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Enter the Agentic Era with Splunk AI Assistant for SPL 1.4

  🚀 Your data just got a serious AI upgrade — are you ready? Say hello to the Agentic Era with the ...

Feel the Splunk Love: Real Stories from Real Customers

Hello Splunk Community,    What’s the best part of hearing how our customers use Splunk? Easy: the positive ...