Hi Team,
Need your expert advise on how can I configure my logstash.conf file to forward only the ERROR OR WARN log lines to Splunk. I have done some online research that a grok filter or wrapping the output with if condition can be used in order the acheive the required result.
I would appreciate if you could share a working example on the same. Many thanks!
Hi @vivek991985,
the logging level doesn't depend on Splunk, it depends on the source, so maybe you should ask to a logstash forum.
Anyway, you can filter in Splunk the not interesting logs following the steps described at https://docs.splunk.com/Documentation/Splunk/8.0.3/Forwarding/Routeandfilterdatad#Filter_event_data_... .
Ciao.
Giuseppe
Thanks very much Giuseppe for your help! Noted.
I do not want to delete it at Splunk side.
I prefer not to send the data with INFO OR DEBUG logging levels to Splunk, therefore, looking forward to getting some clean solution to implement it.
Please advise how logstash.conf should be updated to achieve the required result.
Thanks!
https://answers.splunk.com/answers/59370/filtering-events-using-nullqueue-1.html
Can't you just delete it on the Splunk side?