Deployment Architecture

How to skip six header to index the data in SPlunk using index time configuration

smdasim
Explorer

Hi,
I want to skip first six header lines since they don't have time stamp information to index.please help

McAfee ePO 5.3.1.296
Server name: XXXXXXXX(XXXXXXXX.XXXX.XXXX.XXXXXXX.com.XX)
Platform: Server 6.2
Processors: 4
Architecture: 64-bit
Physical memory: 16383 MB
20180123154844 I #02828 NAIMSERV PSO load: id=7298 ts=6480670

Tags (1)
0 Karma

micahkemp
Champion

I'd suggest sending them to nullQueue at index time. The configuration to do this may look something like the below.

props.conf:

[<sourcetype>]
TRANSFORMS-removeHeaders = removeHeaders

transforms.conf:

[removeHeaders]
REGEX = ^[^0-9]
DEST_KEY = queue
FORMAT = nullQueue

Specifically this will drop any line that does not start with a number.

For general direction, consider reading the Route and filter data documentation.

0 Karma
Get Updates on the Splunk Community!

Observe and Secure All Apps with Splunk

  Join Us for Our Next Tech Talk: Observe and Secure All Apps with SplunkAs organizations continue to innovate ...

Splunk Decoded: Business Transactions vs Business IQ

It’s the morning of Black Friday, and your e-commerce site is handling 10x normal traffic. Orders are flowing, ...

Fastest way to demo Observability

I’ve been having a lot of fun learning about Kubernetes and Observability. I set myself an interesting ...