Deployment Architecture

How to skip six header to index the data in SPlunk using index time configuration

smdasim
Explorer

Hi,
I want to skip first six header lines since they don't have time stamp information to index.please help

McAfee ePO 5.3.1.296
Server name: XXXXXXXX(XXXXXXXX.XXXX.XXXX.XXXXXXX.com.XX)
Platform: Server 6.2
Processors: 4
Architecture: 64-bit
Physical memory: 16383 MB
20180123154844 I #02828 NAIMSERV PSO load: id=7298 ts=6480670

Tags (1)
0 Karma

micahkemp
Champion

I'd suggest sending them to nullQueue at index time. The configuration to do this may look something like the below.

props.conf:

[<sourcetype>]
TRANSFORMS-removeHeaders = removeHeaders

transforms.conf:

[removeHeaders]
REGEX = ^[^0-9]
DEST_KEY = queue
FORMAT = nullQueue

Specifically this will drop any line that does not start with a number.

For general direction, consider reading the Route and filter data documentation.

0 Karma
Get Updates on the Splunk Community!

Detecting Remote Code Executions With the Splunk Threat Research Team

WATCH NOWRemote code execution (RCE) vulnerabilities pose a significant risk to organizations. If exploited, ...

Enter the Splunk Community Dashboard Challenge for Your Chance to Win!

The Splunk Community Dashboard Challenge is underway! This is your chance to showcase your skills in creating ...

.conf24 | Session Scheduler is Live!!

.conf24 is happening June 11 - 14 in Las Vegas, and we are thrilled to announce that the conference catalog ...