Getting Data In

Discard Source type

nikhilagrawal
Path Finder

I have a situation.
I have defined the source type under Deployment server- deployment app>local>prop.conf> as

[source::.../engine-*.log]
TRANSFORMS-null=setnull

Also created under deployment app>local> tranforms.conf which includes:

[setnull]
DEST_KEY = queue
FORMAT = nullQueue

As explained link: http://docs.splunk.com/Documentation/Splunk/4.3/Deploy/Routeandfilterdatad#Filter_event_data_and_sen...

I want to discard the source type for the time being because data is not required for now but might req in future. Created a corresponding stanza in transforms.conf. Set DEST_KEY to "queue" and FORMAT to "nullQueue":
Problem: I am still getting data from that source type. Can you suggest to resolve this?

thanks

Tags (2)
0 Karma

Drainy
Champion

Do you mean source when you say sourcetype?
Did you restart after making those changes?
Also, they will only affect newly indexed data, all your old data will still persist in your index

0 Karma

nikhilagrawal
Path Finder

Can anyone suggest to my above query please?

0 Karma

nikhilagrawal
Path Finder

No It is source type named engine(in my case) and I have restarted the DS. Do I need to restart the forwarder as well? I dont mind with the existing data just want to ignore for future. I have also tried to comment out like:

[source::.../engine-*.log]

sourcetype=engine

TRANSFORMS-null= setnull

Just to check if it discard the data but still showing the indexed data.
Any suggestion?

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Kick the Tires Before You Commit: A Hands-On Tour of the Splunk Observability Cloud ...

Evaluating an enterprise observability platform usually goes like this: fill out a form, get a free trial with ...

Deep insights, no barriers: Splunk Observability Cloud Free Edition

As software delivery cycles continue to accelerate, observability shouldn’t be a luxury — it should be a ...

Monitoring AI Agents with Splunk Observability Cloud

Let’s say I’m running a travel planning AI app in production. A user asks for three concise hotel options in ...