All Apps and Add-ons

Splunk Add-on for AWS: Is there any way to exclude a specific types of events from indexing?

rayar
Contributor

We have the add on installed, is there any way to exclude a specific types of events from indexing ?

Labels (1)
0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rayar,

are you speaking of a Splunk Cloud environment or a Splunk Enterprise on premise?

if Splunk Enterprise on premise, you can follow the instructions at https://docs.splunk.com/Documentation/Splunk/9.0.2/Forwarding/Routeandfilterdatad#Filter_event_data_...

If Splunk Cloud, You have to ask to Splunk Support..

Ciao.

Giuseppe

0 Karma

rayar
Contributor

we are on Splunk Enterprise on premise

is there an option to exclude those events in Splunk Add-on for AWS also ?

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rayar,

no, there isn't any option, only filtering as described in the above link.

Ciao.

Giuseppe

0 Karma

rayar
Contributor

Thanks a lot , I was able to filter the data 

1 more question , how I can define monitoring stanza for s3://aws-controltower-logs-272341124329 .....

I have tested with 

[source::.../aws-controltower-logs-272341124329*/.../*.json.gz]

but I want to add s3://

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @rayar,

I never tried  because I didn't have the necessity to ingest s3 logs and I usually prefer to use sourcetype instead source and, if possible, I hint to use it so you haven't this problem.

Anyway, you could try with * or consider that stanza a regx, so you could escape (with backslash) the first chars.

Ciao.

Giuseppe

0 Karma

rayar
Contributor

the question is how I mark // is part of the path 

I tried to \/\/ but it didn't work 

How to mark the specials characters 

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Splunkbase Unveils New App Listing Management Public Preview

Splunkbase Unveils New App Listing Management Public PreviewWe're thrilled to announce the public preview of ...

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...