Getting Data In

Indexing only specific fields in an event

pdash
Path Finder

I want to index only specific fields like error status in an event and discard the rest. How do I set splunk to do this?

Tags (1)
0 Karma

Ayn
Legend

Splunk has inbuilt functionality by filtering events by sending them to a queue called the nullQueue, which builds on the same concept as /dev/null in UNIX. This works on a per-event basis though, not internally WITHIN events, so your two options as I see it are:

Ayn
Legend

The license counts against how much data is indexed. So, any way you remove data before being indexed results in less data indexed and so results in less data being counted against your license limit.

0 Karma

pdash
Path Finder

yea but anonymizing wont send it to null queue right? I dont want them counting to my indexing volume

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Unlocking Unified Insights: New Gigamon Federated Search App for Splunk

In today’s data-heavy environment, organizations are caught in a data distribution dilemma. As data volumes ...

GA: New Data Management App in Splunk Platform

Streamlining Data Management: Introducing a unified experience in Splunk Managing data at scale shouldn’t feel ...

Announcing Modern Navigation: A New Era of Splunk User Experience

We are excited to introduce the Modern Navigation feature in the Splunk Platform, available to both cloud and ...