Getting Data In

Filtering input data from a udp syslog port

rhuss
Engager

I need some help filtering data from a udp (port 514) syslog input.

I know the source IP and I assume I will need a regex to exclude the records that I want to exclude, but I am confused as to what needs to be added to the config files.

Inputs.conf, props.conf and transforms.conf.

Any help you could offer this new user would be apreciated.

Tags (2)
0 Karma

southeringtonp
Motivator

First, is Splunk listening on port 514, or are you having syslogd write a file for Splunk to index?

syslog-ng and some other syslog daemons can filter for you, but assuming you want Splunk to do the filtering, what you want is nullQueue.

Take a look here: http://www.splunk.com/base/Documentation/4.1.5/Admin/Routeandfilterdata#Discard_specific_events_and_...

and here:
http://answers.splunk.com/questions/96/how-do-i-exclude-some-events-from-being-indexed-by-splunk

Get Updates on the Splunk Community!

SplunkTrust Application Period is Officially OPEN!

It's that time, folks! The application/nomination period for the 2025 SplunkTrust is officially open! If you ...

Splunk Answers Content Calendar, June Edition II

Get ready to dive into Splunk Dashboard panels this week! We'll be tackling common questions around ...

Splunk Observability Cloud's AI Assistant in Action Series: Auditing Compliance and ...

This is the third post in the Splunk Observability Cloud’s AI Assistant in Action series that digs into how to ...