Getting Data In

NullQ output to a File?

meenal901
Communicator

Hi,

I have applied NullQ and IndexQ filtering on my log files at Heavy Forwarder. But the client demands, we do not want to throw away the data but also don't want to index it. For sanity testing, is it possible to send the nullQ output to a flat file which will be stored on a per-day basis?

i.e. instead of writing nullqueue in the transforms, can I write name of file or location?
DEST_KEY = queue
FORMAT = nullQueue

Tags (1)
0 Karma

Ayn
Legend

Sadly no. There is no "write to file" processor.

0 Karma

meenal901
Communicator

Can this be possible:

I route the unwanted data to DEST_KEY=SYSLOG, localhost:541
Then by using SYSLOGNG monitor the 541 port and redirect to a flat file instead of another Splunk instance?

Thanks,
Meenal

0 Karma
Get Updates on the Splunk Community!

Finding Based Detections General Availability

Overview  We’ve come a long way, folks, but here in Enterprise Security 8.4 I’m happy to announce Finding ...

Get Your Hands Dirty (and Your Shoes Comfy): The Splunk Experience

Hands-On Learning and Technical Seminars  Sometimes, you just need to see the code. For those looking for a ...

What’s New in Splunk Observability Cloud: January Feature Highlights & Deep Dives

Splunk Observability Cloud continues to evolve, empowering engineering and operations teams with advanced ...