Deployment Architecture

How to skip six header to index the data in SPlunk using index time configuration

smdasim
Explorer

Hi,
I want to skip first six header lines since they don't have time stamp information to index.please help

McAfee ePO 5.3.1.296
Server name: XXXXXXXX(XXXXXXXX.XXXX.XXXX.XXXXXXX.com.XX)
Platform: Server 6.2
Processors: 4
Architecture: 64-bit
Physical memory: 16383 MB
20180123154844 I #02828 NAIMSERV PSO load: id=7298 ts=6480670

Tags (1)
0 Karma

micahkemp
Champion

I'd suggest sending them to nullQueue at index time. The configuration to do this may look something like the below.

props.conf:

[<sourcetype>]
TRANSFORMS-removeHeaders = removeHeaders

transforms.conf:

[removeHeaders]
REGEX = ^[^0-9]
DEST_KEY = queue
FORMAT = nullQueue

Specifically this will drop any line that does not start with a number.

For general direction, consider reading the Route and filter data documentation.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...