Getting Data In

Stripping header from input file

Explorer

Is there a way to strip the header from a data input? This is coming from a universal forwarder

example

this is garbage
this is also garbage
end of garbage
HEADER DBNAME DBID IO
timestamp testdb 1 100000
..
timestamp last
db 10 500000

I want to not index the first 4 lines (3 starting with > and the column heading line)

0 Karma

Splunk Employee
Splunk Employee

Use Header-based Index-time field extractions:

http://docs.splunk.com/Documentation/Splunk/latest/Data/Extractfieldsfromfileheadersatindextime

In your example above, you could use HEADER_FIELD_LINE_NUMBER=4 or if there is garbage before the field names in the header FIELD_HEADER_REGEX=HEADER\s(.*)

Splunk Employee
Splunk Employee

hello world two
hello world
pet,phone,street
cow,999-9999,taylor
dog,777-7878,balor
cat,656-5637,main
pig,878-1212,pine

transforms.conf

[HEADERNULLQ]
REGEX= (pet|world)
DEST
KEY=queue
FORMAT=nullQueue

props.conf

[your sourcetype]
SHOULDLINEMERGE = False
pulldown
type = 1
TRANSFORMS-HEADERNULLQ=HEADERNULLQ