Getting Data In

Filter data on indexer or heavy forwarder?

Path Finder

Hello, actually we don't have heavy forwarder instance.

Is it possible filter events in indexer when recieve data from UF's? How much performance affect?

Tags (1)
0 Karma

Path Finder

Example to drop events that do not contain $LOG$:


 TRUNCATE = 15000
 TRANSFORMS-filter = event_drop,event_take


DEST_KEY = queue
FORMAT = nullQueue

REGEX = \$\$LOGS\$\$
DEST_KEY = queue
FORMAT = indexQueue 

Hope it help


0 Karma

Path Finder

Thanks for your answer. My other question is how much performance affect if filter events directly on indexer?

0 Karma
Get Updates on the Splunk Community!

.conf24 | Day 0

Hello Splunk Community! My name is Chris, and I'm based in Canberra, Australia's capital, and I travelled for ...

Enhance Security Visibility with Splunk Enterprise Security 7.1 through Threat ...

 (view in My Videos)Struggling with alert fatigue, lack of context, and prioritization around security ...

Troubleshooting the OpenTelemetry Collector

  In this tech talk, you’ll learn how to troubleshoot the OpenTelemetry collector - from checking the ...