- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
I need to filter out some events from a syslog source. All the events that I need to exclude are like this:
Apr 16 11:24:23 ********** 2021-04-16T11:24:23.604+02:00 *************************************** - Modified Query: START TRANSACTION
Can anyone could help?
Thanks in advance
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @marco_massari11
props.conf
[source::"your source"]
TRANSFORMS-filter = eventsDrop
transforms.conf
[eventsDrop]
REGEX = START\sTRANSACTION
DEST_KEY = queue
FORMAT = nullQueue
to help you better I would need the source and sourcetype info
Regards
Alessandro
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @marco_massari11
props.conf
[source::"your source"]
TRANSFORMS-filter = eventsDrop
transforms.conf
[eventsDrop]
REGEX = START\sTRANSACTION
DEST_KEY = queue
FORMAT = nullQueue
to help you better I would need the source and sourcetype info
Regards
Alessandro
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @aasabatini ,
my sourcetype is sourcetype=syslog.
So it should be:
[syslog]
TRANSFORMS-filter = eventsDrop
[eventsDrop]
REGEX = START\sTRANSACTION
DEST_KEY = queue
FORMAT = nullQueue
Is it correct?
Regards
Marco
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes @marco_massari11 , it's correct
props.conf
[syslog]
TRANSFORMS-filter = eventsDrop
transforms.conf
[eventsDrop]
REGEX = START\sTRANSACTION
DEST_KEY = queue
FORMAT = nullQueue
Confirmation solution or karma given is appreciated
Alessandro
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @aasabatini ,
it seems not working. In my props I have already a:
[syslog]
TRANSFORMS-null= **** It exclude an IP in trasnsform.conf.
So I need to do like this?:
[syslog]
TRANSFORMS-null= ****
TRANSFORMS-filter = eventsDrop
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @marco_massari11
no, you need to put your transformations stanza, separated by comma
example:
[syslog]
TRANSFORMS-null= ****,eventsDrop
consider the possibility to filter only data as you need with regex.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @aasabatini ,
my app hasn't the flag on Restart Splunkd. So now it should be work
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi @aasabatini ,
this is my inputs.conf, I don't know if it could help:
[udp://****]
connection_host = ip
index = ***
source = ***
sourcetype = syslog
