- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Route and filter universal forwarder for two apps
Hope everyone is keeping safe.
I'm following this document https://docs.splunk.com/Documentation/Splunk/latest/Forwarding/Routeandfilterdatad (Discard specific events and keep the rest)
The first app is working as expected, however when I've created a second app the filtering is not working
Both apps send data to same index, but the apps are on different servers and different logs. we are using Universal Forwarders
App1
[ ~/etc/deployment-apps/app1/local] $ cat props.conf
[uLinga]
TRANSFORMS-set= setnull,setparsing
[ ~/etc/deployment-apps/app1/local] $ cat transforms.conf
[setnull]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue
[setparsing]
REGEX = INFRASFT
DEST_KEY = queue
FORMAT = indexQueue
App2
[ ~/etc/deployment-apps/app2/local] $ cat props.conf
[Aux]
TRANSFORMS-set = setnull,setparsing
[ ~/etc/deployment-apps/app2/local] $ cat transforms.conf
[setnull]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue
[setparsing]
REGEX = INFO|ERROR|WARN
DEST_KEY = queue
FORMAT = indexQueue
Thank you
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you ,
Managed to sort it out, issue was with the output file on the HF app.
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
![woodcock woodcock](https://community.splunk.com/legacyfs/online/avatars/1493.jpg)
You need to separate your stanza names so that they are not competing, like this:
[~/etc/deployment-apps/app1/local] $ cat props.conf:
[uLinga]
TRANSFORMS-set= uLinga_setnull, uLinga_setparsing
[ ~/etc/deployment-apps/app1/local] $ cat transforms.conf:
[uLinga_setnull]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue
[uLinga_setparsing]
REGEX = INFRASFT
DEST_KEY = queue
FORMAT = indexQueue
[ ~/etc/deployment-apps/app2/local] $ cat props.conf:
[Aux]
TRANSFORMS-set = Auz_setnull, Aux_setparsing
[ ~/etc/deployment-apps/app2/local] $ cat transforms.conf:
[Aux_setnull]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue
[Aux_setparsing]
REGEX = INFO|ERROR|WARN
DEST_KEY = queue
FORMAT = indexQueue
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
![SplunkTrust SplunkTrust](/html/@E48BE65924041B382F8C3220FF058B38/rank_icons/splunk-trust-16.png)
Run:
splunk btool transforms list --debug
You will likely find that you need to uniquely name your transform stanzas otherwise one will overwrite the other...
- Mark as New
- Bookmark Message
- Subscribe to Message
- Mute Message
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
![MuS MuS](https://community.splunk.com/legacyfs/online/avatars/2122.jpg)
Hi MicMoo,
Please post the two apps and their .conf
files so people are able to help you.
cheers, MuS
![](/skins/images/396DDBEEAC295EB5FEC41FF128E8AC0A/responsive_peak/images/icon_anonymous_message.png)