How do i exclude paticular sourcetype from being indexed at my indexer end
Or is there any method to stop them at forwarder end
Hi himapate,
you can stop ingestion inserting disabled=1 in each stanza of your sourcetype in your forwarders inputs.conf, this is easy if you have not many Forwarders or a Deployment Server.
Otherwise, if you want to filter them on the indexers, you have to insert:
in props.conf
[your_sourcetype]
TRANSFORMS-set-nullqueue=set_nullqueue
and in transforms.conf
[set_nullqueue]
REGEX=.
DEST_KEY=queue
FORMAT=nullQueue
and restart Splunk
When you want to disable filter, you have only to comment (#) the TRANSFORMS command in props.conf (obviously restarting Splunk!).
Bye.
Giuseppe
Hi himapate,
you can stop ingestion inserting disabled=1 in each stanza of your sourcetype in your forwarders inputs.conf, this is easy if you have not many Forwarders or a Deployment Server.
Otherwise, if you want to filter them on the indexers, you have to insert:
in props.conf
[your_sourcetype]
TRANSFORMS-set-nullqueue=set_nullqueue
and in transforms.conf
[set_nullqueue]
REGEX=.
DEST_KEY=queue
FORMAT=nullQueue
and restart Splunk
When you want to disable filter, you have only to comment (#) the TRANSFORMS command in props.conf (obviously restarting Splunk!).
Bye.
Giuseppe