Getting Data In

Don't Index Certain Data

Kyle_Brandt
Path Finder

I have turned on security auditing temporarily in Windows and because of this have exceeded my indexing limit.

I was told when purchasing Splunk that you can prevent certain data from being index with filters to prevent this from happening.

How do I create one of these filters?

Tags (2)
0 Karma

csparling
New Member

Is it also possible to not index certain data if you're not using a forwarder? Our setup is pretty simple in that we only have a single Splunk instance running without any forwarding. I've tried a number of times to set up Splunk to drop data based on the client IP by following the steps outlined but not having any luck!

0 Karma

ziegfried
Influencer

You can find the relevant documentation here: http://www.splunk.com/base/Documentation/4.1.7/Admin/Routeandfilterdata

You need to send those events to the nullQueue via transforms.

gkanapathy
Splunk Employee
Splunk Employee

This should help with the "which files" queston: http://www.splunk.com/wiki/Where_do_I_configure_my_Splunk_settings%3F but pretty much if you're using LWF, you filter on the indexer.

0 Karma

Kyle_Brandt
Path Finder

At zeigfried, any chance you could spoonfeed me an example for for wineventlog:security coming in via a light forwarder from certain hosts? Also confused about which props / trans files I should be editing...

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

[Puzzles] Solve, Learn, Repeat: Character substitutions with Regular Expressions

This challenge was first posted on Slack #puzzles channelFor BORE at .conf23, we had a puzzle question which ...

Splunk Community Badges!

  Hey everyone! Ready to earn some serious bragging rights in the community? Along with our existing badges ...

[Puzzles] Solve, Learn, Repeat: Matching cron expressions

This puzzle (first published here) is based on matching timestamps to cron expressions.All the timestamps ...