Getting Data In

Exclude Process ID or application from Indexing

howardevak
New Member

Hi,

We have a need to exclude unwanted events from indexing. The problem is the majority of them are windows file access events which we need to monitor.

What i need to know is if we can exclude eventlogs from indexing based on a process ID or the application running them.

The backup is causing lots of unnecessary events that need excluding.

0 Karma

lguinn2
Legend

What do the events look like? What is the sourcetype and the format? What uniquely identifies these events?

Also, have you considered setting the Windows application log to exclude these events? If Windows isn't logging the details, then Splunk won't either.

0 Karma

howardevak
New Member

Many thanks for your reply Iguinn,

However my problem is this.

I need to index read and write events (which we are currently) but I want to exclude read and write events logged by a particular process (the backup application)

at the moment the backup application is accounting for 95% of all indexed items and there is no requirement for us to keep those indexed.

Can you help further ?

Kind Regards,

Howard

0 Karma

lguinn2
Legend

The answer to your question is yes. In Splunk, this is called filtering. Filtering is performed as the input data is parsed. Usually this happens on the indexer (unless you are using a heavy forwarder).

Here is a link to the relevant bit of documentation: Route and filter data

Here are some similar questions at answers.splunk.com, which show examples that may be useful to you

How do I exclude some events from being indexed by Splunk?

How do I configure Splunk to filter out events I don't want to index?

Hopefully this will help. Feel free to ask more specific questions if you need more details.

Get Updates on the Splunk Community!

Introducing a Smarter Way to Discover Apps on Splunkbase

We’re excited to announce the launch of a foundational enhancement to Splunkbase: App Tiering. Because we’ve ...

How to Send Splunk Observability Alerts to Webex teams in Minutes

As a Developer Evangelist at Splunk, my team and I are constantly tinkering with technology to explore its ...

.conf25 Registration is OPEN!

Ready. Set. Splunk! Your favorite Splunk user event is back and better than ever. Get ready for more technical ...