Getting Data In

Splunk_TA_esxilogs - Why Verbose and Trivia Log are set to NullQueues in transforms.conf

mel_arce
New Member

Hi Splunk Support Team,

  We have utilized the vmware app add-on Splunkbase Splunk_TA_esxilogs and just want to understand the reason behind why verbose/trivia logs are set to NullQueues in transforms.conf, is this a default configuration for this TA? What is the possible risk if these logs won't put to NullQueues. 

#NullQueues
[vmware_generic_level_null]
DEST_KEY = queue
FORMAT = nullQueue
REGEX = (?:verbose|trivia)[:\s]

[vmware_generic_level_null_4x]
DEST_KEY = queue
FORMAT = nullQueue
REGEX = ^\w+\s+\d+\s+[\d:]{8}\s+[^ ]+\s+\w+\s+\d+\s+[\d:]{8}\s.(?:verbose|trivia).

Tags (1)
0 Karma

mel_arce
New Member

Hi,

Much appreciated if someone from Splunk SME or from TA developer provide inputs on the previous query regarding verbose/trivia nullqueue in Splunk TA exsilogs add on for apps for vmware. Thank you!

0 Karma
Register for .conf21 Now! Go Vegas or Go Virtual!

How will you .conf21? You decide! Go in-person in Las Vegas, 10/18-10/21, or go online with .conf21 Virtual, 10/19-10/20.