Getting Data In

How to apply two levels of filtering during parsing in heavy forwarder?

meenal901
Communicator

I have data on which i want to apply 2 level of filtering before indexing
Let the complete data set be called A

Level1 : On complete data i want to keep only events that match some defined patterns ( regular expressions ) ( let the group of pattern be called as B )
So resulting pattern should be A - B

Level 2 : On the filtered events , i want to reject specified defined patterns and KEEP the remaining one ( Let the patterns be called C )

Result should be A - B - C
All this should happen during parsing stage only

0 Karma

MuS
Legend

Hi meenal901,

see the docs about filter event data and send to queue for some good examples on this topic.
Create a nullQueue transform for B and a second for C and it should work for you.

cheers, MuS

0 Karma
Get Updates on the Splunk Community!

Leveraging Detections from the Splunk Threat Research Team & Cisco Talos

  Now On Demand  Stay ahead of today’s evolving threats with the combined power of the Splunk Threat Research ...

New in Splunk Observability Cloud: Automated Archiving for Unused Metrics

Automated Archival is a new capability within Metrics Management; which is a robust usage & cost optimization ...

Calling All Security Pros: Ready to Race Through Boston?

Hey Splunkers, .conf25 is heading to Boston and we’re kicking things off with something bold, competitive, and ...