Getting Data In

Filtering input data from a udp syslog port

rhuss
Engager

I need some help filtering data from a udp (port 514) syslog input.

I know the source IP and I assume I will need a regex to exclude the records that I want to exclude, but I am confused as to what needs to be added to the config files.

Inputs.conf, props.conf and transforms.conf.

Any help you could offer this new user would be apreciated.

Tags (2)
0 Karma

southeringtonp
Motivator

First, is Splunk listening on port 514, or are you having syslogd write a file for Splunk to index?

syslog-ng and some other syslog daemons can filter for you, but assuming you want Splunk to do the filtering, what you want is nullQueue.

Take a look here: http://www.splunk.com/base/Documentation/4.1.5/Admin/Routeandfilterdata#Discard_specific_events_and_...

and here:
http://answers.splunk.com/questions/96/how-do-i-exclude-some-events-from-being-indexed-by-splunk

Get Updates on the Splunk Community!

Data Management Digest – December 2025

Welcome to the December edition of Data Management Digest! As we continue our journey of data innovation, the ...

Index This | What is broken 80% of the time by February?

December 2025 Edition   Hayyy Splunk Education Enthusiasts and the Eternally Curious!    We’re back with this ...

Unlock Faster Time-to-Value on Edge and Ingest Processor with New SPL2 Pipeline ...

Hello Splunk Community,   We're thrilled to share an exciting update that will help you manage your data more ...