i have ingested logs on univesral forwarder by creating file under
/var/log/filename .log & connected to heavy forwarder so now i need to parse data on heavyforwarder & i need to remove particular line from each event.
so i need props .conf & transforms .conf for this
>UF>HF>Indexer
let me know is there any mistakes in stanza
now i need to parse the data
In Heavy Forwarder
props.conf
[source::/var/log/kub1.log]
TRANSFORMS-null= setnull
transforms.conf
[setnull]
REGEX = \S+=openid (expression = i removed a line here from each event)
DEST_KEY = queue
FORMAT = nullQueue
The nullQueue construct will delete events that match the REGEX value. It cannot remove text from an event.
To remove text from an event, use SEDCMD in props.conf.
SEDCMD-remove_openid = s/\S+=openid//
What have you tried so far? How did those efforts fail to meet expectations?
Please share santized sample input and desired output.