All Apps and Add-ons

Limiting ingested fields in Azure Event Hubs

zippo706
Explorer

I"d like to send audit data through an event hub.   However, i want my heavy fwd'r to not send all fields to splunk as 75% of is will be useless and take up all my ingesting quota. 

Is there an easy way to do this?  The data coming in is Azure SQL where i don't beleive i can change data going into the hub.

Labels (1)
Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust

If you want to discard entire events, see https://docs.splunk.com/Documentation/Splunk/8.0.5/Forwarding/Routeandfilterdatad#Filter_event_data_...

If you want to discard parts of events, use SEDCMD in props.conf.

[mysourcetype]
SEDCMD-winevent = s/This event is generated.*//
---
If this reply helps you, Karma would be appreciated.
0 Karma

zippo706
Explorer

Thanks for the info.   can i discard or manipulate fields in an event.   I'm going to speak logstash here and mutate to delete "reallybigfieldIdon'tcareabout"

Tags (1)
0 Karma

richgalloway
SplunkTrust
SplunkTrust
Yes, you can do that with SEDCMD. It will be on the raw event, however, since fields haven't been extracted when SEDCMD runs.
---
If this reply helps you, Karma would be appreciated.

zippo706
Explorer

Thank you, much appreciated.

Tags (1)
0 Karma
Get Updates on the Splunk Community!

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

What You Read The Most: Splunk Lantern’s Most Popular Articles!

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...