All Apps and Add-ons

Remove syslog data in transforms.com

jotne
Builder

I have a Splunk Heavy Forwarder server that is a rsyslog server as well.

When Splunk sees the syslog data, it sets the source type, then the index name before its sent to indexing.

props.conf

 

[rsyslog]
TRANSFORMS-force_vmware = force_sourcetype_vmware, force_ix_vmware

 

 transforms.conf

 

force_sourcetype_vmware]
SOURCE_KEY = MetaData:Host
REGEX = ^host::(10\.30\.31\.\d+)
DEST_KEY = MetaData:Sourcetype
FORMAT = sourcetype::esxi


[force_ix_vmware]
SOURCE_KEY = MetaData:Sourcetype
REGEX = ^sourcetype::(?i)esxi$
DEST_KEY = _MetaData:Index
FORMAT = vmware

 

 

This works fine.

I now like to remove all lines (that are from vmware) that starts with:

 

<134>2021.....
<166>2021.....

 

 

To do so, I made a regex like this:

 

REGEX = ^<(134|166)>2021

 

 

I know that to remove some, I should use:

 

DEST_KEY = queue
FORMAT = nullQueue

 

 

But I do not get it to work.  How to make sure only remove correct data from vmware only?

Labels (1)
0 Karma
Get Updates on the Splunk Community!

Index This | What goes up and never comes down?

January 2026 Edition  Hayyy Splunk Education Enthusiasts and the Eternally Curious!   We’re back with this ...

Splunkers, Pack Your Bags: Why Cisco Live EMEA is Your Next Big Destination

The Power of Two: Splunk &#43; Cisco at "Ludicrous Scale"   You know Splunk. You know Cisco. But have you seen ...

Data Management Digest – January 2026

Welcome to the January 2026 edition of Data Management Digest! Welcome to the January 2026 edition of Data ...