Getting Data In

Universal Forwarder + nullQueue

ruisantos
Path Finder

I'm trying to remove some of the events that should be forwarded to the frontend.
From a configuration perspective everything is OK.

transforms.conf

[nullMon]
REGEX = .
DEST_KEY = queue
FORMAT = nullQueue

[routeRemains]
REGEX = .
DEST_KEY=_TCP_ROUTING
FORMAT= tcp_out

props.conf

[source_log]
TRANSFORMS = nullMon, routeRemains

But I'm receiving everything on the destination host.
Does the Universal Forwarder allow the use of nullQueues?

0 Karma
1 Solution

kristian_kolb
Ultra Champion

No, since nullQueue tranformations take place during the parsing phase, this configuration is only valid on either a Heavy Forwarder or an Indexer.

http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings

/K

View solution in original post

fervin
Path Finder

No, you'd need to configure this transform on an indexer or heavy forwarder. See http://docs.splunk.com/Documentation/Splunk/6.0/Indexer/Howindexingworks

0 Karma

kristian_kolb
Ultra Champion

No, since nullQueue tranformations take place during the parsing phase, this configuration is only valid on either a Heavy Forwarder or an Indexer.

http://wiki.splunk.com/Where_do_I_configure_my_Splunk_settings

/K

Get Updates on the Splunk Community!

Webinar Recap | Revolutionizing IT Operations: The Transformative Power of AI and ML ...

The Transformative Power of AI and ML in Enhancing Observability   In the realm of IT operations, the ...

.conf24 | Registration Open!

Hello, hello! I come bearing good news: Registration for .conf24 is now open!   conf is Splunk’s rad annual ...

ICYMI - Check out the latest releases of Splunk Edge Processor

Splunk is pleased to announce the latest enhancements to Splunk Edge Processor.  HEC Receiver authorization ...