Getting Data In

Is there a way in Splunk Web to not import certain events?

splunk2day
Explorer

I'm trying import an xml and using Line_breakers and such I could get clean events that have my data of interest. Rest of the xml tags (broken events) I want to get rid of during import. Is there a way to do this?! Thanks!

Tags (1)
0 Karma

niketn
Legend

@splunk2day give us more detail of your XML data. Since this kind of filtering will be based on Regular Expression we would need the sample of XML to find start and end pattern of data to index and data to drop from the same event.

Refer to the following Documentation to Discard specific events and keep the rest and Keep specific events and discard the rest

____________________________________________
| makeresults | eval message= "Happy Splunking!!!"
0 Karma

splunk2day
Explorer

Thanks! While this does . provide some inkling, it's not a complete solution as I'm using the web and not entirely sure how this applies to the web, during manual import. My xml data looks like below -

I'm only interested in the part between the attributes tags, rest everything i want to filter out. I'm able to break it into meaningful events for me and just looking for the filter out way to i can totally eliminate having to import the meta data.

*** . unable to post xml here - it all formats funny ****
hopefully this gives u some idea

metadata tags level 1
metadata tags level 2
metadata tags level 3
xml fragment of interested that i can extract
closing and reopening meta data tags to my data of interest can repeat that i want to get rid of for a cleaner event imports ..

0 Karma

woodcock
Esteemed Legend

You can easily post XML by pasting it, highlighting it and clicking on the 1010101 "code" button in the style/editor ribbon above your text window.

0 Karma
Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...