Getting Data In
Highlighted

filtering syslog from only one host

Explorer

I have multiple hosts sending syslog information to splunk via its listener. However, one of these hosts, I'd like to on retain certain information.

Is the process the same (props.conf, transforms.conf) for filtering only a specific hosts syslog events?

Tags (2)
0 Karma
Highlighted

Re: filtering syslog from only one host

Esteemed Legend

Yes, you would use this stanza header:

[host::YourHost]
0 Karma