Getting Data In

Is it possible to filter events after indexing, but before they are forwarded?


I'm gathering the _internal index from several hundred remote hosts, but the only events I want to collect centrally are warnings and errors. Is it possible to filter what events get forwarded to the central indexer?



Tags (1)
0 Karma

Esteemed Legend

The _internal index is not really "yours" to mess with and I highly advise against even trying. Doing so will surely cause some apps not to work correctly (e.g. SoS, etc.), might cause Splunk support to be hampered in assisting you, and could even (conceivably) break your support agreement. It does not impact your license and shouldn't be too much disk space so why not just leave well enough alone?

0 Karma
State of Splunk Careers

Access the Splunk Careers Report to see real data that shows how Splunk mastery increases your value and job satisfaction.

Find out what your skills are worth!