Getting Data In

Exclude Sourcetype from being indexed

himapate
Explorer

How do i exclude paticular sourcetype from being indexed at my indexer end
Or is there any method to stop them at forwarder end

0 Karma
1 Solution

gcusello
SplunkTrust
SplunkTrust

Hi himapate,
you can stop ingestion inserting disabled=1 in each stanza of your sourcetype in your forwarders inputs.conf, this is easy if you have not many Forwarders or a Deployment Server.

Otherwise, if you want to filter them on the indexers, you have to insert:
in props.conf

[your_sourcetype]
TRANSFORMS-set-nullqueue=set_nullqueue

and in transforms.conf

[set_nullqueue]
REGEX=.
DEST_KEY=queue
FORMAT=nullQueue

and restart Splunk

When you want to disable filter, you have only to comment (#) the TRANSFORMS command in props.conf (obviously restarting Splunk!).

Bye.
Giuseppe

View solution in original post

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi himapate,
you can stop ingestion inserting disabled=1 in each stanza of your sourcetype in your forwarders inputs.conf, this is easy if you have not many Forwarders or a Deployment Server.

Otherwise, if you want to filter them on the indexers, you have to insert:
in props.conf

[your_sourcetype]
TRANSFORMS-set-nullqueue=set_nullqueue

and in transforms.conf

[set_nullqueue]
REGEX=.
DEST_KEY=queue
FORMAT=nullQueue

and restart Splunk

When you want to disable filter, you have only to comment (#) the TRANSFORMS command in props.conf (obviously restarting Splunk!).

Bye.
Giuseppe

0 Karma
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...