Getting Data In

Can I filter logs coming from forwarders with config files under \etc\system or logs can be filtered just from heavy forwarders?

CsungyiPepi19
New Member

Can I filter logs coming from forwarders with config files under \etc\system or logs can be filtered just from heavy forwarders? I installed splunk forwarders and wanted to filter logs so I have tried to create props.conf and transforms.conf under \etc\System\local but there was no effect. When I install heavy forwarders it worked deploying config files (under \etc\deploymentapps).

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi CsungyiPepi19,
logs can be filtered only on Indexers and (when present) on Heavy Forwarders as you can see at https://docs.splunk.com/Documentation/Splunk/7.3.2/Forwarding/Routeandfilterdatad.
There's only one filter that can be applied to Universal Forwarders and it's related to wineventlogs because it's possible to apply a whitelist and/or a blacklist to the logs to ingest.

Ijn addition, avoid to put configurations in $SPLUNK_HOME/etc/system/local, but put always conf files in dedicated apps called Technical Add-ons (TAs) because in this way you can manage them with a Deployment Server, if instead you put conf files in systel local you have to manually manage them.

When you say "When I install heavy forwarders it worked deploying config files (under \etc\deploymentapps)." this means that you're using your Heavy Forwarder as a Deployment Server, but it isn't a good configuration if you have more than 50 client to manage because in this case you need a dedicated Deplyment Server.
You can find more information at https://docs.splunk.com/Documentation/Splunk/7.3.2/Updating/Aboutdeploymentserver .

Ciao.
Giuseppe

View solution in original post

0 Karma

CsungyiPepi19
New Member

mille grazie Giuseppe!

CsP

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi CsungyiPepi19,
logs can be filtered only on Indexers and (when present) on Heavy Forwarders as you can see at https://docs.splunk.com/Documentation/Splunk/7.3.2/Forwarding/Routeandfilterdatad.
There's only one filter that can be applied to Universal Forwarders and it's related to wineventlogs because it's possible to apply a whitelist and/or a blacklist to the logs to ingest.

Ijn addition, avoid to put configurations in $SPLUNK_HOME/etc/system/local, but put always conf files in dedicated apps called Technical Add-ons (TAs) because in this way you can manage them with a Deployment Server, if instead you put conf files in systel local you have to manually manage them.

When you say "When I install heavy forwarders it worked deploying config files (under \etc\deploymentapps)." this means that you're using your Heavy Forwarder as a Deployment Server, but it isn't a good configuration if you have more than 50 client to manage because in this case you need a dedicated Deplyment Server.
You can find more information at https://docs.splunk.com/Documentation/Splunk/7.3.2/Updating/Aboutdeploymentserver .

Ciao.
Giuseppe

0 Karma

CsungyiPepi19
New Member

Mille grazie Giuseppe!
CsP

0 Karma
Get Updates on the Splunk Community!

Updated Team Landing Page in Splunk Observability

We’re making some changes to the team landing page in Splunk Observability, based on your feedback. The ...

New! Splunk Observability Search Enhancements for Splunk APM Services/Traces and ...

Regardless of where you are in Splunk Observability, you can search for relevant APM targets including service ...

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...