Getting Data In

Events filter on heavy forwarder doesn't work

nicofantinato
Path Finder

Hi all,

we are monitoring some log files in a Windows directory; we'd like to keep only events containing the word FAILURE and discard the rest, so we set a filter in our two heavy forwarders but it doesn't work, we ingest all data and nothing is discarded. Here our configuration files:

props.conf

 

 

[bpm_metastorm]
DATETIME_CONFIG=CURRENT
SHOULD_LINEMERGE=false
LINE_BREAKER=([\r\n]+)
NO_BINARY_CHECK=true
CHARSET=UTF-8
disabled=false
TRANSFORMS-set=bpm_null,bpm_parsing

 

 

transforms.conf

 

 

[bpm_null]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue

[bpm_parsing]
REGEX = FAILURE
DEST_KEY = queue
FORMAT = indexQueue

 

 

There aren't other stanzas with same names as above, so it shouldn't be a name conflict problem; and we set another similar filter to another sourcetype, that worked while this new one not. Do you have any suggestions?

Thanks in advance

Labels (3)
0 Karma
Get Updates on the Splunk Community!

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud

Introduction to Splunk Observability Cloud - Building a Resilient Hybrid Cloud  In today’s fast-paced digital ...

Observability protocols to know about

Observability protocols define the specifications or formats for collecting, encoding, transporting, and ...

Take Your Breath Away with Splunk Risk-Based Alerting (RBA)

WATCH NOW!The Splunk Guide to Risk-Based Alerting is here to empower your SOC like never before. Join Haylee ...