Getting Data In

How can I exclude data from being ingested by the universal forwarder?

neophyte01
Engager

Hello all,

I have recently set up Splunk to monitor /var/log/messages.
There is one event in this log that I would like to exclude.
The event itself really does not matter.
I would just like to know how I can keep certain types of data
from getting into Splunk, without ignoring the files which the data comes from.

Please help.

bobmorning
Engager

We have an outside scanning agency that is constantly doing nmap like scans of our external perimeter.  It is generating a log of log data on the perimeter CISCO firewalls.   We know the IPs that the scanning is coming from; is there a way to tell the forwarders to NOT forward that log data from the firewalls for those IPs?

Thanks for any insights on this.  Our Splunk SME are looking at CRIBL to do this but reading this thread makes me believe there are configuration settings that might address this?

V/R

Bob M.

0 Karma

niketn
Legend

@neophyte01, you can use nullQueue for this using transforms.conf and props.conf

Refer to documentation: http://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad#Discard_specific_e...

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"

neophyte01
Engager

@niketnilay thanks. I believe this is what I need.

0 Karma

niketn
Legend

@neophyte01, I have converted to answer. Please accept if your issue is resolved.

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

somesoni2
Revered Legend

And this will be configured on Indexer/Heavy forwarder, one to which your universal forwarder sends data to.

Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Casting Call: Compete in Cyber Games

Lights, Camera, SecOps: Apply to Compete in Cyber Games     Think you have what it takes to beat the clock? ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...

How Edge Processor's Durable Queue Works

Edge Processor sits in one of the most consequential places in any Splunk pipeline: between your data sources ...