Getting Data In
Highlighted

can I use a prefilter to collect the syslog which I really need before put them in the database

Communicator

I want to collect the syslog which I really need before put them in the database ,can I set a prefilter ?

thank you !

Tags (2)
0 Karma
Highlighted

Re: can I use a prefilter to collect the syslog which I really need before put them in the database

Splunk Employee
Splunk Employee

yep. you can add a configuration in props and transforms on the indexer to filter the events.

see nullqueue filtering
http://docs.splunk.com/Documentation/Splunk/4.3.3/Deploy/Routeandfilterdatad#Filter_event_data_and_s...

View solution in original post