Getting Data In

Is there a way to filter only a certain type of log from websphere to get logged to splunk?

sowmyak
New Member

I'm trying to add debug and error logs from websphere to splunk, but it consuming a lot of space. My aim is to reduce the memory consumed, so I want to avoid unnecessary logs from wbsphere to enter the splunk. All my websphere logs are first saved in system.out file which is then redirected to splunk. Please suggest if there is a way to do this.

Tags (1)
0 Karma

inventsekar
SplunkTrust
SplunkTrust

Hi Sowmyak,
on the inputs.conf, you can add a whitelist to select the files or blacklist to filter out some files.
Let us know more info, like your current inputs.conf, to filter out filenames, etc.. so that we can help you on the inputs.conf update..

https://www.splunk.com/blog/2009/07/09/monitoring-input-files-with-a-white-list.html
http://www.splunk.com/base/Documentation/latest/Admin/WhitelistAndBlacklistRules

thanks and best regards,
Sekar

PS - If this or any post helped you in any way, pls consider upvoting, thanks for reading !
0 Karma
Get Updates on the Splunk Community!

Splunk Enterprise Security 8.0.2 Availability: On cloud and On-premise!

A few months ago, we released Splunk Enterprise Security 8.0 for our cloud customers. Today, we are excited to ...

Logs to Metrics

Logs and Metrics Logs are generally unstructured text or structured events emitted by applications and written ...

Developer Spotlight with Paul Stout

Welcome to our very first developer spotlight release series where we'll feature some awesome Splunk ...