Knowledge Management

How to configure sc4s (Splunk connect for syslog SC4S) to drop certain events?

Elbald97
Explorer

Hello,

I have an Splunk Connect for Syslog (SC4S) server that retrieves logs from a source and transmits them to Splunk indexers.

But in order to reduce the number of events, I want to filter the logs at the sc4s level. Note that the sc4s tool uses syslog-ng for filtering and parsing.


The use case is as follows:
when an event arrives on the sc4s server and contains an ip address of 10.9.40.245, the event is dropped.

Elbald97_2-1734353403956.png

Does anyone have any idea how to create this filter on SC4S?

Thank you.

Labels (1)
0 Karma

Elbald97
Explorer

Thank you.

It's worked for me.

0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

What Is Splunk? Here’s What You Can Do with Splunk

Hey Splunk Community, we know you know Splunk. You likely leverage its unparalleled ability to ingest, index, ...

Level Up Your .conf25: Splunk Arcade Comes to Boston

With .conf25 right around the corner in Boston, there’s a lot to look forward to — inspiring keynotes, ...

Manual Instrumentation with Splunk Observability Cloud: How to Instrument Frontend ...

Although it might seem daunting, as we’ve seen in this series, manual instrumentation can be straightforward ...