Getting Data In

Ingest Action to include message

yuvaraj_m91
Loves-to-Learn Lots

I am using ingest action to filter the log message before being indexed in splunk..

I want to include the message that matches only the keyword :ERROR: and :FATAL: rest all of the messages should not be indexed.

Whereas in splunk ingest action has the filter to only exclude message not the include

Labels (1)
Tags (1)
0 Karma

PickleRick
SplunkTrust
SplunkTrust

If you're not hellbent of doing it with Ingest Actions, you can just use transforms to filter out all events except for the ones you want

https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad

In your case you'd need to first have a "match-all" transform rerouting all data to nullQueue, and then a transform maching only ERROR/FATAL events sending the events to indexQueue.

yuvaraj_m91
Loves-to-Learn Lots

we are using splunk cloud UI

0 Karma

PickleRick
SplunkTrust
SplunkTrust

Doesn't matter. You can make an app with those settings and deploy it to your Cloud instance.

0 Karma

deepakc
Builder

Hi 

You might then be able to apply a regex pattern to say to NOT not match ERROR or FATAL, therefore keep them, and discard the rest. 

Try this 
^(?!.*(ERROR|FATAL)).*$

0 Karma

yuvaraj_m91
Loves-to-Learn Lots

I tried this but still i am seeing other events being ingested apart from :ERROR: and :FATAL:

0 Karma

deepakc
Builder

Suggestions made by @PickleRick  are probably best to go with. 

In terms of it still not working - you will most likely need to adjust the reg-ex pattern based on your logs.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas

Why Splunk Customers Should Attend Cisco Live 2026 Las Vegas     Cisco Live 2026 is almost here, and this ...

What Is the Name of the USB Key Inserted by Bob Smith? (BOTS Hint, Not the Answer)

Hello Splunkers,   So you searched, “what is the name of the usb key inserted by bob smith?”  Not gonna lie… ...

Automating Threat Operations and Threat Hunting with Recorded Future

    Automating Threat Operations and Threat Hunting with Recorded Future June 29, 2026 | Register   Is your ...