Security

Forward only WARN OR ERROR log lines to splunk

vivek991985
New Member

Hi Team,

Need your expert advise on how can I configure my logstash.conf file to forward only the ERROR OR WARN log lines to Splunk. I have done some online research that a grok filter or wrapping the output with if condition can be used in order the acheive the required result.

I would appreciate if you could share a working example on the same. Many thanks!

0 Karma

gcusello
SplunkTrust
SplunkTrust

Hi @vivek991985,
the logging level doesn't depend on Splunk, it depends on the source, so maybe you should ask to a logstash forum.

Anyway, you can filter in Splunk the not interesting logs following the steps described at https://docs.splunk.com/Documentation/Splunk/8.0.3/Forwarding/Routeandfilterdatad#Filter_event_data_... .

Ciao.
Giuseppe

0 Karma

vivek991985
New Member

Thanks very much Giuseppe for your help! Noted.

0 Karma

vivek991985
New Member

I do not want to delete it at Splunk side.

I prefer not to send the data with INFO OR DEBUG logging levels to Splunk, therefore, looking forward to getting some clean solution to implement it.

Please advise how logstash.conf should be updated to achieve the required result.

Thanks!

0 Karma

to4kawa
Ultra Champion
0 Karma
Career Survey
First 500 qualified respondents will receive a $20 gift card! Tell us about your professional Splunk journey.

Can’t make it to .conf25? Join us online!

Get Updates on the Splunk Community!

Leveraging Automated Threat Analysis Across the Splunk Ecosystem

Are you leveraging automation to its fullest potential in your threat detection strategy?Our upcoming Security ...

Can’t Make It to Boston? Stream .conf25 and Learn with Haya Husain

Boston may be buzzing this September with Splunk University and .conf25, but you don’t have to pack a bag to ...

Splunk Lantern’s Guide to The Most Popular .conf25 Sessions

Splunk Lantern is a Splunk customer success center that provides advice from Splunk experts on valuable data ...