Getting Data In

Filtering event on splunk fowarder

rbw78
Communicator

Hello,

Here's the situation.
I have an equipement sending 2 kinds of events with UDP syslog to a splunk fowarder and then send it to a splunk server in TCP.
I would like to filter events on the splunk fowarder with the outputs.conf or inputs.conf files by gathering only 1 kind of log.
i'd see this is possible on the splunk server directly but i want to minimize the impact on the bandwidth and not sending useless logs for nothing.

Is there a way to do that via a regex or specific char on the event ?

Thanks.

Tags (2)
0 Karma
1 Solution

MHibbin
Influencer

Have you read .... http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Routeandfilterdatad

This should get you going? should be fairly simple if you know what you want to exclude

View solution in original post

MHibbin
Influencer

Have you read .... http://docs.splunk.com/Documentation/Splunk/latest/Deploy/Routeandfilterdatad

This should get you going? should be fairly simple if you know what you want to exclude

MHibbin
Influencer

so they are all just applications that run on top of another platform

0 Karma

MHibbin
Influencer

basically no, Splunk do not have any appliances, the "Heavy" forwarder is simply a regular instance of Splunk that has forwarding enabled... to add some more info a "Light" forwarder is a regular instance of Splunk that has some features disabled such as Splunkweb and indexing. And "Universal" forwarder is a completely stripped down instance of Splunk with no webUI, no python etc. Unfortunately as the docs say unless you simply want to filter on the metadata of host/source/sourcetype, you can not use a light or universal forwarder (i.e. for your event filtering).

rbw78
Communicator

Well i didn't see this page, thanks.

But i want to do this on a UniversalSplunkFowarder, not a heavy fowarder which is i guess a physical splunk appliance, correct ?

0 Karma
Get Updates on the Splunk Community!

Built-in Service Level Objectives Management to Bridge the Gap Between Service & ...

Wednesday, May 29, 2024  |  11AM PST / 2PM ESTRegister now and join us to learn more about how you can ...

Get Your Exclusive Splunk Certified Cybersecurity Defense Engineer Certification at ...

We’re excited to announce a new Splunk certification exam being released at .conf24! If you’re headed to Vegas ...

Share Your Ideas & Meet the Lantern team at .Conf! Plus All of This Month’s New ...

Splunk Lantern is Splunk’s customer success center that provides advice from Splunk experts on valuable data ...