Splunk 6.1 Linux indexers feeding server with master license.
I am trying to filter out repetitive lines from a log file before they are indexed. Need to configure the 3 conf files: inputs, props and transform.
The server where the log file is located(different from indexer server where conf files are located): mmd5
mmd5 path/log: /var/log/*/CheckPointReconciler.log*
Log line I want to filter out to nullQueue ( filter on 'Reading')
2015-12-30 2:02:12.736 14181:4 INFO job_id none main Reading checkpoint directory /mm/feeder/chkpt