Getting Data In

How to apply two levels of filtering during parsing in heavy forwarder?

meenal901
Communicator

I have data on which i want to apply 2 level of filtering before indexing
Let the complete data set be called A

Level1 : On complete data i want to keep only events that match some defined patterns ( regular expressions ) ( let the group of pattern be called as B )
So resulting pattern should be A - B

Level 2 : On the filtered events , i want to reject specified defined patterns and KEEP the remaining one ( Let the patterns be called C )

Result should be A - B - C
All this should happen during parsing stage only

0 Karma

MuS
Legend

Hi meenal901,

see the docs about filter event data and send to queue for some good examples on this topic.
Create a nullQueue transform for B and a second for C and it should work for you.

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In September, the Splunk Threat Research Team had two releases of new security content via the Enterprise ...

New in Observability - Improvements to Custom Metrics SLOs, Log Observer Connect & ...

The latest enhancements to the Splunk observability portfolio deliver improved SLO management accuracy, better ...

Improve Data Pipelines Using Splunk Data Management

  Register Now   This Tech Talk will explore the pipeline management offerings Edge Processor and Ingest ...