All Apps and Add-ons

change input.conf

vumanhtai
Path Finder

Hi!
input.conf in Splunk-TA-Window
this default
"[WinEventLog://System]
disabled = 0
start_from = oldest
current_only = 0
checkpointInterval = 5
index = wineventlog
renderXml=false"

I just want to get log error. how do i change it!

0 Karma

sandyIscream
Communicator

You need to write props.conf and transforms.conf when you want to filter any data.

In your case you need construct your props.conf like below.

[sourcetype]
TRANSFORMS-set =setnull, Error

transforms.conf

[setnull] --------------------------------------this is direct all the unwanted data to null queue. (Same as dev/null for linux)
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue

[Error] ---------------------- It will filter all the events which have ERROR keyword in them and redirect them to your index
REGEX = ERROR
DEST_KEY = queue
FORMAT = indexQueue

0 Karma

mayurr98
Super Champion
0 Karma

vumanhtai
Path Finder

thank! you

0 Karma

mayurr98
Super Champion

hey @vumanhtai

does this help you?

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...