Cant get DEBUG messages filtered out at all on splunkforwarder.
Did create $SPLUNKHOME/etc/system/local/transforms.conf
[debug-setnull]
REGEX = DEBUG
DEST_KEY = queue
FORMAT = nullQueue
Did copy props.conf drom default to $SPLUNKHOME/etc/system/local/props.conf
[source::.../*.log]
TRANSFORMS = debug-setnull
restarted splunkforwarder
Result: Still get DEBUG Messages sent to Splunkserver.
Don't know whi it not works. Does forwarder works not with transforms.conf?
if run check debug, get following message.
splunk btool check –debug
-> No spec file for: /usr/local/splunk/splunkforwarder/etc/system/local/transforms.conf
Thanks for help
Peter
You need to set this up on the indexer not the forwarder as that's where these rules are applied.
Thanks works when is configured at indexer.