Getting Data In

How to filter out the first 2 lines of an event?

shan_santosh
Explorer

I have a VB script to get Local users from Admin group. The event data from this script by default adds the below 2 lines to the event.

Microsoft (R) Windows Script Host Version 5.8
Copyright (C) Microsoft Corporation. All rights reserved.

How to get rid of these unwanted lines?

0 Karma

somesoni2
Revered Legend

If you own the script, update the same to remove these unwanted lines from the output.

If that's not possible, you can use event filtering method to drop those lines from indexing

http://docs.splunk.com/Documentation/Splunk/6.4.3/Forwarding/Routeandfilterdatad#Filter_and_route_ev...
https://answers.splunk.com/answers/37423/how-to-configure-a-forwarder-to-filter-and-send-the-specifi...

0 Karma

sundareshr
Legend
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...