- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
How to skip six header to index the data in SPlunk using index time configuration
smdasim
Explorer
02-07-2018
05:56 PM
Hi,
I want to skip first six header lines since they don't have time stamp information to index.please help
McAfee ePO 5.3.1.296
Server name: XXXXXXXX(XXXXXXXX.XXXX.XXXX.XXXXXXX.com.XX)
Platform: Server 6.2
Processors: 4
Architecture: 64-bit
Physical memory: 16383 MB
20180123154844 I #02828 NAIMSERV PSO load: id=7298 ts=6480670
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
micahkemp
Champion
02-07-2018
06:04 PM
I'd suggest sending them to nullQueue at index time. The configuration to do this may look something like the below.
props.conf:
[<sourcetype>]
TRANSFORMS-removeHeaders = removeHeaders
transforms.conf:
[removeHeaders]
REGEX = ^[^0-9]
DEST_KEY = queue
FORMAT = nullQueue
Specifically this will drop any line that does not start with a number.
For general direction, consider reading the Route and filter data documentation.
