Getting Data In

How to configure props.conf and transforms.conf to filter events with LogLevel=INFO to nullQueue?

Norling80
Path Finder

Hi guys.

I have a JBoss ServerLog that contains events with the following LogLevels:
INFO
WARNING
ERROR
SEVERE

I don't want to index events with LogLevel=INFO, how should my props.conf and transforms.conf look like?

1 Solution

gfuente
Motivator

Thanks

Then you can use this config:

props.conf:

[yourjbosssourcetype]
 TRANSFORMS-info=eliminate-info

transforms.conf

[eliminate-info]
 REGEX=\d*\sINFO\s\[
 DEST_KEY=queue
 FORMAT=nullQueue

Regards

View solution in original post

gfuente
Motivator

Thanks

Then you can use this config:

props.conf:

[yourjbosssourcetype]
 TRANSFORMS-info=eliminate-info

transforms.conf

[eliminate-info]
 REGEX=\d*\sINFO\s\[
 DEST_KEY=queue
 FORMAT=nullQueue

Regards

Norling80
Path Finder

Worked like a charm, with a minor update to the regex:

REGEX=\d*\sINFO\s+\[

Thanks you very much!

gfuente
Motivator

Is would be useful if you add some sample events, as is needed to define a regex to filter out those events

regards

Norling80
Path Finder

Sure, here you go. LogLevels in bold:

2015-03-05 09:49:45,994 +0100 INFO org.apache.cxf.services.ServerService.ServerPort.Server Inbound Message
2015-03-05 09:49:45,227 +0100 INFO LOG_gamings.system.GameServlet Redirecting the request from Game : gamename_mobile_html_sw to new game flow
2015-03-05 06:35:14,808 +0100 ERROR org.jboss.as.ejb3 javax.ejb.EJBTransactionRolledbackException:

0 Karma

ppablo
Retired

Hi @Norling80

Just wanted to follow up and see if @gfuente's answer below solved your question. If yes, don't forget to accept his answer and upvote it. Thanks!

Patrick

Get Updates on the Splunk Community!

Enterprise Security Content Update (ESCU) | New Releases

In December, the Splunk Threat Research Team had 1 release of new security content via the Enterprise Security ...

Why am I not seeing the finding in Splunk Enterprise Security Analyst Queue?

(This is the first of a series of 2 blogs). Splunk Enterprise Security is a fantastic tool that offers robust ...

Index This | What are the 12 Days of Splunk-mas?

December 2024 Edition Hayyy Splunk Education Enthusiasts and the Eternally Curious!  We’re back with another ...