Splunk Cloud Platform

Filtering Sourcetypes which contains an information the information as small

anandhalagaras1
Communicator

Hi Team,

In our environment I can see few of the sourcetypes are coming with *small* from both the internal as well as from non-internal indexes. So  hence these logs are not required for us so I want to disable them before ingestion time itself by placing the props and transforms in the indexer level.

So any sourcetype has a keyword with "small" might be like too_small , os_tab_small or anytype then the logs should not be ingested into Splunk. So kindly provide with the props and transforms for the same.

 

 

 

Labels (3)
0 Karma

scelikok
SplunkTrust
SplunkTrust

Hi @anandhalagaras1,

Splunk will automatically try to classify your data if you don't specify a sourcetype. For small sets of data, such as less than 100 events, Splunk will label the data as "too_small". 

You should find these sources and specify sourcetype for them.

If this reply helps you an upvote and "Accept as Solution" is appreciated.
0 Karma

anandhalagaras1
Communicator

@scelikok ,

Thank you for your swift response.

So i want to filter out the logs completely if it contains something like *small* in the sourcetype from splunk ingestion so what would be the props and transforms for the same. Since saving some Licenses i want to filter out those logs which comes with sourcetype "*small*"

0 Karma

anandhalagaras1
Communicator

@scelikok ,

Just checked the query as you mentioned i can see around 50+ sourcetypes contains with _*small* in the sourcetype so these would of not much important i believe (Correct me if i am wrong?) so I am planning to stop ingesting those logs into Splunk. So any sourcetype which has *small* in it then those logs should not be ingested into Splunk. So kindly help with the props and transforms.

0 Karma
Get Updates on the Splunk Community!

Introducing the 2024 SplunkTrust!

Hello, Splunk Community! We are beyond thrilled to announce our newest group of SplunkTrust members!  The ...

Introducing the 2024 Splunk MVPs!

We are excited to announce the 2024 cohort of the Splunk MVP program. Splunk MVPs are passionate members of ...

Splunk Custom Visualizations App End of Life

The Splunk Custom Visualizations apps End of Life for SimpleXML will reach end of support on Dec 21, 2024, ...