I have a .out DUMP file generated by Bamboo Logs -- that I want to monitor in Splunk.
I need to filter out certain content and then push over the rest to Standard Out via the universal forwarder onto the indexer.
What is the best way to go about this ?
A few options :
i) Convert the .out file to a .log file and filter out content using some process (not sure how) I could use a nullQueue setup on the indexer that will filter out whatever should not be indexed in splunk
ii) Point the configuration on the universal forwarder DIRECTLY to the .out file
Is the file a binary file? If not then you don't need to convert to .log. Just monitor the file and then you use props/transforms.conf to look for what you don't want sent to the indexer and forward that to the nullQueue.